CyberRota Analysis
This is a low severity vulnerability with a CVSS score of 3.4. It affects Exchange. Exploitation may require the attacker to be authenticated.
CVE
CVE-2023-0657
Severity
LOW
CVSS
3.4
EPSS
0.30%
Exchange
Original NVD Description
A flaw was found in Keycloak. This issue occurs due to improperly enforcing token types when validating signatures locally. This could allow an authenticated attacker to exchange a logout token for an access token and possibly gain access to data outside of enforced permissions.