CVE-2023-6544
Keycloak: authorization bypass
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.
Se encontró una falla en el paquete Keycloak. Este problema se produce debido a una expresión regular permisiva codificada para el filtrado que permite a los hosts registrar un cliente dinámico. Un usuario malintencionado con suficiente información sobre el entorno podría poner en peligro un entorno con este registro dinámico de cliente específico y esta configuración de TrustedDomain previamente no autorizada.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2023-12-06 CVE Reserved
- 2024-04-25 CVE Published
- 2024-04-26 EPSS Updated
- 2024-11-24 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-625: Permissive Regular Expression
CAPEC
References (9)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2024:1860 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1861 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1862 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1864 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1866 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1867 | 2024-04-25 | |
https://access.redhat.com/errata/RHSA-2024:1868 | 2024-04-25 | |
https://access.redhat.com/security/cve/CVE-2023-6544 | 2024-04-16 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2253116 | 2024-04-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Build Keycloak Search vendor "Redhat" for product "Build Keycloak" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Red Hat Single Sign On Search vendor "Redhat" for product "Red Hat Single Sign On" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Rhosemc Search vendor "Redhat" for product "Rhosemc" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Enterprise Linux Search vendor "Redhat" for product "Enterprise Linux" | * | - |
Affected
|