CVE-2023-6291High· 7.1▾ TwilightA flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
keycloak < 22.0.7single_sign-onopenshift_container_platform = 4.11openshift_container_platform = 4.12openshift_container_platform_for_ibm_z = 4.9openshift_container_platform_for_ibm_z = 4.10openshift_container_platform_for_linuxone = 4.9openshift_container_platform_for_linuxone = 4.10openshift_container_platform_for_power = 4.9openshift_container_platform_for_power = 4.10single_sign-on = 7.6migration_toolkit_for_applications = 6.0migration_toolkit_for_applications = 7.0Upgrade past the affected range:
keycloak 22.0.7Connected by shared product, vendor, weakness, or advisory.
CVE-2023-6927Medium· 4.6A flaw was found in Keycloak
CVE-2023-6563High· 7.7An unconstrained memory consumption vulnerability was discovered in Keycloak
CVE-2025-3501High· 8.2A flaw was found in Keycloak
CVE-2025-2559Medium· 4.9A flaw was found in Keycloak
CVE-2024-1249High· 7.4A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages
CVE-2023-6717Medium· 6.0A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk