CVE-2023-6927
18.12.2023, 23:15
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
Vendor | Product | Version |
---|---|---|
redhat | keycloak | - |
redhat | single_sign-on | 7.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References