VYPR
High severity7.1NVD Advisory· Published Jan 26, 2024· Updated Jun 17, 2026

CVE-2023-6291

CVE-2023-6291

Description

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.keycloak:keycloak-servicesMaven
< 23.0.323.0.3

Affected products

31
  • Red Hat/Red Hat build of Keycloak 22.0.7v5
    cpe:/a:redhat:build_keycloak:22
  • cpe:/a:redhat:build_keycloak:22::el9
    Range: 22-9
  • Red Hat/Red Hat JBoss Data Grid 7v5
    cpe:/a:redhat:jboss_data_grid:7
  • Red Hat/Red Hat Data Grid 8v5
    cpe:/a:redhat:jboss_data_grid:8
  • cpe:/a:redhat:jboss_enterprise_application_platform:6
  • cpe:/a:redhat:jboss_enterprise_bpms_platform:7
  • cpe:/a:redhat:jboss_enterprise_brms_platform:7
  • Red Hat/Red Hat Fuse 7v5
    cpe:/a:redhat:jboss_fuse:7
  • cpe:/a:redhat:migration_toolkit_applications:6+ 3 more
    • cpe:/a:redhat:migration_toolkit_applications:6
    • cpe:/a:redhat:migration_toolkit_applications:7
    • cpe:2.3:a:redhat:migration_toolkit_for_applications:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:migration_toolkit_for_applications:7.0:*:*:*:*:*:*:*
  • Red Hat/Single Sign Oncpe-rescue7 versions
    cpe:/a:redhat:red_hat_single_sign_on:7.6+ 6 more
    • cpe:/a:redhat:red_hat_single_sign_on:7.6
    • cpe:/a:redhat:red_hat_single_sign_on:7.6.6
    • cpe:/a:redhat:red_hat_single_sign_on:7.6::el7range: 0:18.0.12-1.redhat_00001.1.el7sso
    • cpe:/a:redhat:red_hat_single_sign_on:7.6::el8range: 0:18.0.12-1.redhat_00001.1.el8sso
    • cpe:/a:redhat:red_hat_single_sign_on:7.6::el9range: 0:18.0.12-1.redhat_00001.1.el9sso
    • cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
    • cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*
  • Red Hat/RHEL-8 based Middleware Containersv5
    cpe:/a:redhat:rhosemc:1.0::el8
    Range: 7.6-41
  • cpe:/a:redhat:serverless:1
  • cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:*
    Range: <22.0.7
  • cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.9:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

18

News mentions

0

No linked articles in our index yet.