
A small PoC for the Keycloak vulnerability CVE-2023-0264
Keycloak vulnerability that allows session hijacking during authorization code flow
See https://github.com/advisories/GHSA-9g98-5mj6-f9mv
./run-keycloak-container.shalice and mallory with ./create-users.shpython3 -m http.server 8000alice and password test in session 1 and copy the session id from the promptmallory and password test in session 2 and paste the session id from alice into the
prompt (and press OK)alice in session 2 from mallory