Keycloak: redirect_uri validation bypass
Summary
| CVE | CVE-2023-6291 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-01-26 15:15:08 UTC |
| Updated | 2026-09-22 04:17:56 UTC |
| Description | A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users. |
Risk And Classification
Primary CVSS: v3.1 7.1 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Problem Types: CWE-601 | CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| 3.1 | [email protected] | Secondary | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
| 3.1 | CNA | CVSS | 7.1 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
LowCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 8.0 | All | All | All |
| Application | Redhat | Keycloak | All | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.11 | All | All | All |
| Application | Redhat | Openshift Container Platform | 4.12 | All | All | All |
| Application | Redhat | Openshift Container Platform For Ibm Z | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Ibm Z | 4.9 | All | All | All |
| Application | Redhat | Openshift Container Platform For Linuxone | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Linuxone | 4.9 | All | All | All |
| Application | Redhat | Openshift Container Platform For Power | 4.10 | All | All | All |
| Application | Redhat | Openshift Container Platform For Power | 4.9 | All | All | All |
| Application | Redhat | Single Sign-on | - | All | All | All |
| Application | Redhat | Single Sign-on | 7.6 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Build Of Keycloak 22 | unaffected 22.0.7-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 22 | unaffected 22-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 22 | unaffected 22-9 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 22.0.7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 7 | unaffected 0:18.0.11-2.redhat_00003.1.el7sso * rpm | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 7 | unaffected 0:18.0.12-1.redhat_00001.1.el7sso * rpm | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 8 | unaffected 0:18.0.11-2.redhat_00003.1.el8sso * rpm | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 8 | unaffected 0:18.0.12-1.redhat_00001.1.el8sso * rpm | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 9 | unaffected 0:18.0.11-2.redhat_00003.1.el9sso * rpm | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7.6 For RHEL 9 | unaffected 0:18.0.12-1.redhat_00001.1.el9sso * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.6-38 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.6.6-2 * rpm | Not specified |
| CNA | Red Hat | RHEL-8 Based Middleware Containers | unaffected 7.6-41 * rpm | Not specified |
| CNA | Red Hat | Single Sign-On 7.6.6 | Not specified | Not specified |
| CNA | Red Hat | Migration Toolkit For Applications 6 | Not specified | Not specified |
| CNA | Red Hat | Migration Toolkit For Applications 7 | Not specified | Not specified |
| CNA | Red Hat | OpenShift Serverless | Not specified | Not specified |
| CNA | Red Hat | Red Hat Data Grid 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Decision Manager 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Fuse 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat JBoss Data Grid 7 | Not specified | Not specified |
| CNA | Red Hat | Red Hat JBoss Enterprise Application Platform 6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Process Automation 7 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2024:0798 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| cve-details | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| access.redhat.com/errata/RHSA-2024:0801 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:0800 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:0804 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| 2251407 – (CVE-2023-6291) CVE-2023-6291 keycloak: redirect_uri validation bypass | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | Issue Tracking, Vendor Advisory |
| access.redhat.com/errata/RHSA-2024:0799 | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| Red Hat | af854a3a-2127-422b-91ae-364da2661108 | access.redhat.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2023-11-24T00:00:00.000Z | Reported to Red Hat. |
| CNA | 2023-12-14T00:00:00.000Z | Made public. |
Workarounds
CNA: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Legacy QID Mappings
- 996431 Java (Maven) Security Update for org.keycloak:keycloak-services (GHSA-mpwq-j3xf-7m5w)