MEDIUM 5.4 Maven
Keycloak Authorization Bypass vulnerability
GHSA-46c8-635v-68r2 · CVE-2023-6544
Published · Modified
Description
Due to a permissive regular expression hardcoded for filtering allowed hosts to register a dynamic client, a malicious user with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized.
Acknowledgements:
Special thanks to Bastian Kanbach for reporting this issue and helping us improve our security.
References
- WEB https://github.com/keycloak/keycloak/security/advisories/GHSA-46c8-635v-68r2
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-6544
- WEB https://access.redhat.com/errata/RHSA-2024:1860
- WEB https://access.redhat.com/errata/RHSA-2024:1861
- WEB https://access.redhat.com/errata/RHSA-2024:1862
- WEB https://access.redhat.com/errata/RHSA-2024:1864
- WEB https://access.redhat.com/errata/RHSA-2024:1866
- WEB https://access.redhat.com/errata/RHSA-2024:1867
- WEB https://access.redhat.com/errata/RHSA-2024:1868
- WEB https://access.redhat.com/security/cve/CVE-2023-6544
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2253116
- PACKAGE https://github.com/keycloak/keycloak
Ready to move
Start Securing
Free, no credit card | First findings in minutes