CVE-2023-6134
14.12.2023, 22:15
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
Vendor | Product | Version |
---|---|---|
redhat | single_sign-on | 𝑥 < 7.6 |
redhat | keycloak | 𝑥 < 22.0.7 |
redhat | openshift_container_platform | 4.11 |
redhat | openshift_container_platform | 4.12 |
redhat | openshift_container_platform_for_power | 4.9 |
redhat | openshift_container_platform_for_power | 4.10 |
redhat | openshift_container_platform_ibm_z_systems | 4.9 |
redhat | openshift_container_platform_ibm_z_systems | 4.10 |
redhat | single_sign-on | - |
𝑥
= Vulnerable software versions
References