cbcvebase.
CVE-2023-6291
published 2024-01-26

CVE-2023-6291: A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may…

PriorityP337high7.1CVSS 3.1
AVNACLPRNUIRSCCLILAL
EPSS
0.95%
57.3th percentile
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

Affected

13 ranges
VendorProductVersion rangeFixed in
googlechrome_chrome
redhatkeycloak< 22.0.722.0.7
redhatmigration_toolkit_for_applications
redhatmigration_toolkit_for_applications
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_ibm_z
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatsingle_sign-on

CVSS provenance

nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.