6.1
CVSSv3

CVE-2023-6927

Published: 18/12/2023 Updated: 14/02/2024
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

A flaw was found in Keycloak. This issue may allow an malicious user to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak -

redhat single sign-on 7.0

Vendor Advisories

Synopsis Moderate: Red Hat Single Sign-On 766 security update on RHEL 9 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 9Red Hat P ...
Synopsis Moderate: Red Hat Single Sign-On 766 security update on RHEL 8 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 8Red Hat P ...
Synopsis Moderate: Red Hat Single Sign-On 766 security update on RHEL 7 Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 7Red Hat P ...
Synopsis Moderate: Red Hat build of Keycloak 2208 images enhancement and security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat build of Keycloak 2208 images running on OpenShift Container PlatformRed Hat Product Security has rated this update as having a security impact of Moderate ...
Synopsis Moderate: Red Hat Single Sign-On 766 for OpenShift image enhancement and security update Type/Severity Security Advisory: Moderate Topic A new image is available for Red Hat Single Sign-On 766, running on OpenShift Container Platform 310 and 311, and 43Red Hat Product Security has rated this update as having a security impact ...
Synopsis Moderate: Red Hat Single Sign-On 766 security update Type/Severity Security Advisory: Moderate Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base sco ...
Synopsis Moderate: Red Hat build of Keycloak 2208 enhancement and security update Type/Severity Security Advisory: Moderate Topic Red Hat build of Keycloak 2208 is now available from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) base ...
Description<!---->A flaw was found in Keycloak This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_postjwt" which could be used to bypass the security patch implemented to address CVE-2023-6134A flaw was found in Keycloak This issue may allow an attacker to steal ...