Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6544

Опубликовано: 16 апр. 2024
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

Отчет

Due to the high complexity of this attack, Red Hat considers this a Moderate impact.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-625

EPSS

Процентиль: 53%
0.00299
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 2 года назад

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

CVSS3: 5.4
debian
почти 2 года назад

A flaw was found in the Keycloak package. This issue occurs due to a p ...

CVSS3: 5.4
github
почти 2 года назад

Keycloak Authorization Bypass vulnerability

CVSS3: 5.4
fstec
почти 2 года назад

Уязвимость компонента Client Registration Handler программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 53%
0.00299
Низкий

5.4 Medium

CVSS3