---
id: CVE-2023-6291
title: A flaw was found in the redirect_uri validation logic in Keycloak
summary: >-
  A flaw was found in the redirect_uri validation logic in Keycloak. This issue
  may allow a bypass of otherwise explicitly allowed hosts. A successful attack
  may lead to an access token being stolen, making it possible for the attacker
  to …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'
cwe:
  - CWE-601
vendor: redhat
product: keycloak
affected:
  - keycloak < 22.0.7
  - single_sign-on
  - openshift_container_platform = 4.11
  - openshift_container_platform = 4.12
  - openshift_container_platform_for_ibm_z = 4.9
  - openshift_container_platform_for_ibm_z = 4.10
  - openshift_container_platform_for_linuxone = 4.9
  - openshift_container_platform_for_linuxone = 4.10
  - openshift_container_platform_for_power = 4.9
  - openshift_container_platform_for_power = 4.10
  - single_sign-on = 7.6
  - migration_toolkit_for_applications = 6.0
  - migration_toolkit_for_applications = 7.0
patched:
  - keycloak 22.0.7
published: '2024-01-26'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T04:17:56.317'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6291'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2023:7854'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7855'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7856'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7857'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7858'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7860'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7861'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0798'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0799'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0800'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0801'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:0804'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6291'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2251407'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2023:7854'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7855'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7856'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7857'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7858'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7860'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2023:7861'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0798'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0799'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0800'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0801'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:0804'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6291'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2251407'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6291.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-6291'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6291'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
epss: 0.0095
epssPercentile: 0.59562
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-11-13T14:56:46.143772Z'
ingestedAt: '2026-09-22T03:57:48.899Z'
---

## Overview

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

## Affected

- `keycloak < 22.0.7`
- `single_sign-on`
- `openshift_container_platform = 4.11`
- `openshift_container_platform = 4.12`
- `openshift_container_platform_for_ibm_z = 4.9`
- `openshift_container_platform_for_ibm_z = 4.10`
- `openshift_container_platform_for_linuxone = 4.9`
- `openshift_container_platform_for_linuxone = 4.10`
- `openshift_container_platform_for_power = 4.9`
- `openshift_container_platform_for_power = 4.10`
- `single_sign-on = 7.6`
- `migration_toolkit_for_applications = 6.0`
- `migration_toolkit_for_applications = 7.0`

## Remediation

Upgrade past the affected range:

- `keycloak 22.0.7`

## Vendor advisories

- **RHSA-2023:7854** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 7 Server · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7854)
- **RHSA-2024:0798** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 7 Server · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0798)
- **RHSA-2023:7857** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7857)
- **RHSA-2024:0801** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0801)
- **RHSA-2023:7856** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 8 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7856)
- **RHSA-2024:0799** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 8 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0799)
- **RHSA-2023:7861** · Red Hat · fixed in: Red Hat build of Keycloak 22 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7861)
- **RHSA-2023:7855** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 9 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7855)
- **RHSA-2024:0800** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 9 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0800)
- **RHSA-2024:0804** · Red Hat · fixed in: Red Hat Single Sign-On 7 · released 2024-02-13 · [advisory](https://access.redhat.com/errata/RHSA-2024:0804)
- **RHSA-2023:7860** · Red Hat · fixed in: Red Hat build of Keycloak 22.0.7 · released 2023-12-14 · [advisory](https://access.redhat.com/errata/RHSA-2023:7860)
- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 6 · no fix planned: Migration Toolkit for Applications 6 · updated 2026-09-22 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6291.json)
