{"id":"CVE-2023-6717","title":"A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk","summary":"A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This is…","severity":"medium","cvss":6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L","cwe":["CWE-79"],"vendor":"Red Hat","product":"keycloak","affected":["keycloak < 22.0.10","keycloak >= 24.0.0 < 24.0.3","keycloak","rhbk/keycloak-operator-bundle (all versions)","rhbk/keycloak-rhel9 (all versions)","rhbk/keycloak-rhel9-operator (all versions)","keycloak","openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)","openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)","openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)","openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)","openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)","openshift-serverless-1/logic-operator-bundle (all versions)","openshift-serverless-1/logic-rhel8-operator (all versions)","openshift-serverless-1/logic-swf-builder-rhel8 (all versions)","openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)","rhpam_7.13.5_async","mta/mta-ui-rhel9 (all versions)","mta/mta-ui-rhel9","keycloak (all versions)","keycloak-core","keycloak-core","keycloak (all versions)","keycloak (all versions)","rhdh/rhdh-hub-rhel9","keycloak (all versions)","keycloak (all versions)","keycloak","org.keycloak-keycloak-parent","rh-sso7-keycloak","keycloak","keycloak","keycloak","openshift-gitops-1/gitops-rhel8-operator (all versions)","keycloak (all versions)","rh-sso7-keycloak (all versions)"],"published":"2024-04-25","updated":"2026-09-11","sourceUpdated":"2026-09-11T02:18:31.073","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-6717","references":[{"url":"https://access.redhat.com/errata/RHSA-2024:1353","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1867","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1868","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:2945","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:4057","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6717","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253952","label":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2024:1867","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:1868","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:2945","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/errata/RHSA-2024:4057","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://access.redhat.com/security/cve/CVE-2023-6717","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2253952","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6717.json"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-6717"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6717"}],"tags":["nvd","cve.org","csaf","vex","red-hat"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2024-04-25T19:15:14.697195Z"},"epss":0.00711,"epssPercentile":0.52129,"ingestedAt":"2026-08-05T11:47:23.203Z","patched":["openshift_serverless 1.33","build_of_keycloak 22","rhpam_7_13_5_async","amq_broker 7","build_of_keycloak 22.0.10"],"slug":"CVE-2023-6717","body":"## Overview\n\nA flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **RHSA-2024:4057** · Red Hat · fixed in: Red Hat OpenShift Serverless 1.33 · released 2024-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2024:4057)\n- **RHSA-2024:1867** · Red Hat · fixed in: Red Hat build of Keycloak 22 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1867)\n- **RHSA-2024:1353** · Red Hat · fixed in: RHPAM 7.13.5 async · released 2024-03-18 · [advisory](https://access.redhat.com/errata/RHSA-2024:1353)\n- **RHSA-2024:2945** · Red Hat · fixed in: Red Hat AMQ Broker 7 · released 2024-05-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:2945)\n- **RHSA-2024:1868** · Red Hat · fixed in: Red Hat build of Keycloak 22.0.10 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1868)\n- **Red Hat VEX** · Moderate · affected: Migration Toolkit for Applications 6, Red Hat build of Apicurio Registry 2, Red Hat Data Grid 8, Red Hat Decision Manager 7, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, … · no fix planned: Red Hat JBoss Enterprise Application Platform 6, Migration Toolkit for Applications 6, Red Hat Data Grid 8, Red Hat Fuse 7, … · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6717.json)","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}