Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6544

Опубликовано: 16 апр. 2024
Источник: redhat
CVSS3: 5.4

Описание

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

Отчет

Due to the high complexity of this attack, Red Hat considers this a Moderate impact.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-625

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

CVSS3: 5.4
debian
больше 2 лет назад

A flaw was found in the Keycloak package. This issue occurs due to a p ...

CVSS3: 5.4
github
больше 2 лет назад

Keycloak Authorization Bypass vulnerability

CVSS3: 5.4
fstec
больше 2 лет назад

Уязвимость компонента Client Registration Handler программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

5.4 Medium

CVSS3