CVE Feed

    Dashboard / CVE / CVE-2024-0560

    CVE-2024-0560

    A vulnerability was found in 3Scale, when used with Keycloak 15 (or RHSSO 7.5.0) and superiors. When the auth_type is use_3scale_oidc_issuer_endpoint, the Token Introspection policy discovers the Token Introspection endpoint from the token_introspection_endpoint field, but the field was removed on RH-SSO 7.5. As a result, the policy doesn't inspect tokens, it determines that all tokens are valid.

    Published:Feb 28, 2024
    Last Modified:Nov 20, 2025
    EPS:Feb 28, 2024
    EPSS Score:0.00208
    CVSS Score:6.3

    Affected Products

    Vendor
    Redhat
    Product
    3scale
    Vendor
    Redhat
    Product
    Keycloak
    Vendor
    Redhat
    Product
    Red Hat 3scale Amp

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High