CVE-2023-6927
Last modified
CVE-2023-6927 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.. EPSS estimates a 1.11% chance of exploitation in the next 30 days.
Description
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Keycloak | All versions |
| Redhat | Single Sign-On | 7.0 |
References
- https://access.redhat.com/security/cve/CVE-2023-6927Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255027Issue Tracking, Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2023-6927Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2255027Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-6927?
How severe is CVE-2023-6927?
How do I fix CVE-2023-6927?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-6921Blind SQL Injection vulnerability in PrestaShow Google Integ…9.1
- CVE-2023-6922The Under Construction / Maintenance Mode from Acurax plugin…6.5
- CVE-2023-6923The Matomo Analytics – Ethical Stats. Powerful Insights. plu…6.1
- CVE-2023-6924The Photo Gallery by 10Web plugin for WordPress is vulnerabl…4.8
- CVE-2023-6925The Unlimited Addons for WPBakery Page Builder plugin for Wo…7.2
- CVE-2023-6926 There is an OS command injection vulnerability in Crestron …7.8
- CVE-2023-6928 EuroTel ETL3100 versions v01c01 and v01x37 does not limit t…9.8
- CVE-2023-6929 EuroTel ETL3100 versions v01c01 and v01x37 are vulnerab…9.8
- CVE-2023-6930 EuroTel ETL3100 versions v01c01 and v01x37 suffer f…9.8
- CVE-2023-6931A heap out-of-bounds write vulnerability in the Linux kernel…7
- CVE-2023-6932A use-after-free vulnerability in the Linux kernel's ipv4: i…7
- CVE-2023-6933The Better Search Replace plugin for WordPress is vulnerable…8.8
Are you affected by CVE-2023-6927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
