cbcvebase.
CVE-2023-6291
published 2024-01-26

CVE-2023-6291: A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may…

high7.1CVSS 3.1
AVNACLPRNUIRSCCLILAL
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

Affected

13 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
redhatkeycloak< 22.0.722.0.7
redhatmigration_toolkit_for_applications
redhatmigration_toolkit_for_applications
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatsingle_sign-on