{"id":"CVE-2023-6291","title":"A flaw was found in the redirect_uri validation logic in Keycloak","summary":"A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L","cwe":["CWE-601"],"vendor":"redhat","product":"keycloak","affected":["keycloak < 22.0.7","single_sign-on","openshift_container_platform = 4.11","openshift_container_platform = 4.12","openshift_container_platform_for_ibm_z = 4.9","openshift_container_platform_for_ibm_z = 4.10","openshift_container_platform_for_linuxone = 4.9","openshift_container_platform_for_linuxone = 4.10","openshift_container_platform_for_power = 4.9","openshift_container_platform_for_power = 4.10","single_sign-on = 7.6","migration_toolkit_for_applications = 6.0","migration_toolkit_for_applications = 7.0"],"patched":["keycloak 22.0.7"],"published":"2024-01-26","updated":"2026-09-22","sourceUpdated":"2026-09-22T04:17:56.317","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-6291","references":[{"url":"https://access.redhat.com/errata/RHSA-2023:7854","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7855","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7856","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7857","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7858","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7860","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7861","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0798","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0799","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0800","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0801","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:0804","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6291","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2251407","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2023:7854","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7855","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7856","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7857","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7858","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7860","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2023:7861","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0798","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0799","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0800","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0801","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:0804","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6291","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2251407","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6291.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-6291"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6291"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"epss":0.0095,"epssPercentile":0.59761,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2024-11-13T14:56:46.143772Z"},"ingestedAt":"2026-09-22T03:57:48.899Z","slug":"CVE-2023-6291","body":"## Overview\n\nA flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.\n\n## Affected\n\n- `keycloak < 22.0.7`\n- `single_sign-on`\n- `openshift_container_platform = 4.11`\n- `openshift_container_platform = 4.12`\n- `openshift_container_platform_for_ibm_z = 4.9`\n- `openshift_container_platform_for_ibm_z = 4.10`\n- `openshift_container_platform_for_linuxone = 4.9`\n- `openshift_container_platform_for_linuxone = 4.10`\n- `openshift_container_platform_for_power = 4.9`\n- `openshift_container_platform_for_power = 4.10`\n- `single_sign-on = 7.6`\n- `migration_toolkit_for_applications = 6.0`\n- `migration_toolkit_for_applications = 7.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `keycloak 22.0.7`\n\n## Vendor advisories\n\n- **RHSA-2023:7854** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 7 Server · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7854)\n- **RHSA-2024:0798** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 7 Server · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0798)\n- **RHSA-2023:7857** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7857)\n- **RHSA-2024:0801** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0801)\n- **RHSA-2023:7856** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 8 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7856)\n- **RHSA-2024:0799** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 8 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0799)\n- **RHSA-2023:7861** · Red Hat · fixed in: Red Hat build of Keycloak 22 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7861)\n- **RHSA-2023:7855** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 9 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7855)\n- **RHSA-2024:0800** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 9 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0800)\n- **RHSA-2024:0804** · Red Hat · fixed in: Red Hat Single Sign-On 7 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0804)\n- **RHSA-2023:7860** · Red Hat · fixed in: Red Hat build of Keycloak 22.0.7 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7860)\n- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 6 · no fix planned: Migration Toolkit for Applications 6 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6291.json)","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}