CVE-2023-6291

HIGHCVSS 7.1/10EPSS 0.95%

Last modified

CVE-2023-6291 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. EPSS estimates a 0.95% chance of exploitation in the next 30 days.

Description

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

Metrics

CVSS 3.1
7.1/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

EPSS Probability
0.95%

56.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
RedhatKeycloak< 22.0.7
RedhatSingle Sign-OnAll versions
RedhatOpenshift Container Platform4.11
RedhatOpenshift Container Platform4.12
RedhatOpenshift Container Platform For Ibm Z4.9
RedhatOpenshift Container Platform For Ibm Z4.10
RedhatOpenshift Container Platform For Linuxone4.9
RedhatOpenshift Container Platform For Linuxone4.10
RedhatOpenshift Container Platform For Power4.9
RedhatOpenshift Container Platform For Power4.10
RedhatSingle Sign-On7.6
RedhatMigration Toolkit For Applications6.0
RedhatMigration Toolkit For Applications7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-6291?
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
How severe is CVE-2023-6291?
CVE-2023-6291 has a CVSS score of 7.1/10 (HIGH severity). The EPSS model estimates a 0.95% probability of exploitation in the next 30 days.
How do I fix CVE-2023-6291?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-6291?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST