CVE-2023-6291
Keycloak: redirect_uri validation bypass
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Productos afectados
Red Hat · Migration Toolkit for Applications 6Red Hat · Migration Toolkit for Applications 7Red Hat · OpenShift ServerlessRed Hat · Red Hat build of Keycloak 22Red Hat · Red Hat build of Keycloak 22.0.7Red Hat · Red Hat Data Grid 8Red Hat · Red Hat Decision Manager 7Red Hat · Red Hat Fuse 7Red Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Enterprise Application Platform 6Red Hat · Red Hat Process Automation 7Red Hat · Red Hat Single Sign-On 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 8Red Hat · Red Hat Single Sign-On 7.6 for RHEL 9Red Hat · RHEL-8 based Middleware ContainersRed Hat · Single Sign-On 7.6.6¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://access.redhat.com/errata/RHSA-2023:7854https://access.redhat.com/errata/RHSA-2023:7855https://access.redhat.com/errata/RHSA-2023:7856https://access.redhat.com/errata/RHSA-2023:7857https://access.redhat.com/errata/RHSA-2023:7858https://access.redhat.com/errata/RHSA-2023:7860https://access.redhat.com/errata/RHSA-2023:7861https://access.redhat.com/errata/RHSA-2024:0798https://access.redhat.com/errata/RHSA-2024:0799https://access.redhat.com/errata/RHSA-2024:0800https://access.redhat.com/errata/RHSA-2024:0801https://access.redhat.com/errata/RHSA-2024:0804