CVE-2023-6927
MEDIUMRedhat Keycloak < 23.0.4 - Open Redirect
Title source: ruleDescription
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
References (14)
Scores
CVSS v3
4.6
EPSS
0.0084
EPSS Percentile
74.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Classification
CWE
CWE-601
Status
published
Affected Products (3)
redhat/keycloak
redhat/single_sign-on
org.keycloak/keycloak-core
< 23.0.4Maven
Timeline
Published
Dec 18, 2023
Tracked Since
Feb 18, 2026