5.4
CVSSv3

CVE-2023-6134

Published: 14/12/2023 Updated: 14/02/2024
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an malicious user to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat single_sign-on

redhat keycloak

redhat openshift_container_platform 4.11

redhat openshift_container_platform 4.12

redhat openshift_container_platform_for_power 4.9

redhat openshift_container_platform_for_power 4.10

redhat openshift_container_platform_ibm_z_systems 4.9

redhat openshift_container_platform_ibm_z_systems 4.10

redhat single sign-on -

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Important: Red Hat build of Keycloak 2207 enhancement and security update Type/Severity Security Advisory: Important Topic Red Hat build of Keycloak 2207 is now available from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) b ...
Synopsis Important: Red Hat build of Keycloak 2207 images enhancement and security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat build of Keycloak 2207 images running on OpenShift Container PlatformRed Hat Product Security has rated this update as having a security impact of Import ...
Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 9Red Hat ...
Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 8 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 8Red Hat ...
Synopsis Important: Red Hat Single Sign-On 766 for OpenShift image enhancement and security update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 766, running on OpenShift Container Platform 310 and 311, and 43Red Hat Product Security has rated this update as having a security impa ...
Synopsis Important: Red Hat Single Sign-On 766 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Description<!---->A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks This flaw is the result of an incomplete fix for CVE-2020-10748A flaw ...