Medium severity4.5NVD Advisory· Published Dec 23, 2023· Updated Jun 17, 2026
CVE-2023-49594
CVE-2023-49594
Description
An information disclosure vulnerability exists in the challenge functionality of instipod DuoUniversalKeycloakAuthenticator 1.0.7 plugin. A specially crafted HTTP request can lead to a disclosure of sensitive information. A user logging into Keycloak using DuoUniversalKeycloakAuthenticator plugin triggers this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:michaelkelly:duouniversalkeycloakauthenticator:*:*:*:*:*:keycloak:*:*Range: <1.0.8
<=1.0.7+ 1 more
- (no CPE)range: <=1.0.7
- (no CPE)range: 1.0.7
Patches
Vulnerability mechanics
References
3- talosintelligence.com/vulnerability_reports/TALOS-2023-1907nvdExploitThird Party Advisory
- github.com/instipod/DuoUniversalKeycloakAuthenticator/releases/tag/1.0.8nvdRelease Notes
- www.talosintelligence.com/vulnerability_reports/TALOS-2023-1907nvd
News mentions
0No linked articles in our index yet.