Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6291

Опубликовано: 14 дек. 2023
Источник: redhat
CVSS3: 7.1

Описание

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6keycloakWill not fix
Migration Toolkit for Applications 7keycloakNot affected
OpenShift ServerlesskeycloakNot affected
Red Hat Data Grid 8keycloakNot affected
Red Hat Decision Manager 7keycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat JBoss Data Grid 7keycloakNot affected
Red Hat JBoss Enterprise Application Platform 6rh-sso7-keycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat build of Keycloak 22rhbk/keycloak-operator-bundleFixedRHSA-2023:786114.12.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2251407keycloak: redirect_uri validation bypass

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
около 2 лет назад

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

CVSS3: 7.1
debian
около 2 лет назад

A flaw was found in the redirect_uri validation logic in Keycloak. Thi ...

CVSS3: 7.1
github
около 2 лет назад

The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restricted

7.1 High

CVSS3