CVE-2023-6291

CVSS 3.1 Score 7.1 of 10 (high)

Details

Published Jan 26, 2024
Updated: Feb 14, 2024
CWE ID 601

Summary

CVE-2023-6291 is a vulnerability affecting Keycloak's redirect_uri validation logic. This issue allows for bypassing explicitly allowed hosts, potentially allowing an attacker to steal an access token. If exploited, the attacker could impersonate other users and gain unauthorized access to protected resources. This vulnerability poses a significant risk to security and requires immediate attention from Keycloak users for patching or mitigation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Keycloak
  • Red Hat Openshift Container Platform
  • Red Hat Single Sign-On

Affected Vendors

  • Red Hat