Uploaded image for project: 'WildFly Elytron'
  1. WildFly Elytron
  2. ELY-2743

CVE-2023-6236: OIDC app attempting to access the second tenant, the user should be prompted to log in

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Major Major
    • 2.4.0.Final
    • None
    • None
    • None

      When attempting to access the second tenant, the user should be prompted to log in again since the second tenant is secured with different OIDC configuration (e.g., with a different Keycloak realm).

      The underlying issue is a bug in OidcSessionTokenStore when determining if a cached token should be used or not. This logic needs to be updated to take into account the new "provider-url" option in addition to the "realm" option.

      See https://access.redhat.com/security/cve/CVE-2023-6236.

              fjuma1@redhat.com Farah Juma
              fjuma1@redhat.com Farah Juma
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: