CVE-2023-6291
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Jan 26, 2024
Updated: Feb 14, 2024
CWE ID 601
Summary
CVE-2023-6291 is a vulnerability affecting Keycloak's redirect_uri validation logic. This issue allows for bypassing explicitly allowed hosts, potentially allowing an attacker to steal an access token. If exploited, the attacker could impersonate other users and gain unauthorized access to protected resources. This vulnerability poses a significant risk to security and requires immediate attention from Keycloak users for patching or mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Keycloak
- Red Hat Openshift Container Platform
- Red Hat Single Sign-On
Affected Vendors
- Red Hat