---
id: CVE-2023-6717
title: >-
  A flaw was found in the SAML client registration in Keycloak that could allow
  an administrator to register malicious JavaScript URIs as Assertion Consumer
  Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk
summary: >-
  A flaw was found in the SAML client registration in Keycloak that could allow
  an administrator to register malicious JavaScript URIs as Assertion Consumer
  Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk.
  This is…
severity: medium
cvss: 6
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L'
cwe:
  - CWE-79
vendor: Red Hat
product: keycloak
affected:
  - keycloak < 22.0.10
  - keycloak >= 24.0.0 < 24.0.3
  - keycloak
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - keycloak
  - openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)
  - openshift-serverless-1/logic-operator-bundle (all versions)
  - openshift-serverless-1/logic-rhel8-operator (all versions)
  - openshift-serverless-1/logic-swf-builder-rhel8 (all versions)
  - openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)
  - rhpam_7.13.5_async
  - mta/mta-ui-rhel9 (all versions)
  - mta/mta-ui-rhel9
  - keycloak (all versions)
  - keycloak-core
  - keycloak-core
  - keycloak (all versions)
  - keycloak (all versions)
  - rhdh/rhdh-hub-rhel9
  - keycloak (all versions)
  - keycloak (all versions)
  - keycloak
  - org.keycloak-keycloak-parent
  - rh-sso7-keycloak
  - keycloak
  - keycloak
  - keycloak
  - openshift-gitops-1/gitops-rhel8-operator (all versions)
  - keycloak (all versions)
  - rh-sso7-keycloak (all versions)
published: '2024-04-25'
updated: '2026-09-11'
sourceUpdated: '2026-09-11T02:18:31.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6717'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:1353'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4057'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6717'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2253952'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:4057'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2023-6717'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2253952'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6717.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2023-6717'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2023-6717'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2024-04-25T19:15:14.697195Z'
epss: 0.00711
epssPercentile: 0.51712
ingestedAt: '2026-08-05T11:47:23.203Z'
patched:
  - openshift_serverless 1.33
  - build_of_keycloak 22
  - rhpam_7_13_5_async
  - amq_broker 7
  - build_of_keycloak 22.0.10
---

## Overview

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:4057** · Red Hat · fixed in: Red Hat OpenShift Serverless 1.33 · released 2024-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2024:4057)
- **RHSA-2024:1867** · Red Hat · fixed in: Red Hat build of Keycloak 22 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1867)
- **RHSA-2024:1353** · Red Hat · fixed in: RHPAM 7.13.5 async · released 2024-03-18 · [advisory](https://access.redhat.com/errata/RHSA-2024:1353)
- **RHSA-2024:2945** · Red Hat · fixed in: Red Hat AMQ Broker 7 · released 2024-05-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:2945)
- **RHSA-2024:1868** · Red Hat · fixed in: Red Hat build of Keycloak 22.0.10 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1868)
- **Red Hat VEX** · Moderate · affected: Migration Toolkit for Applications 6, Red Hat build of Apicurio Registry 2, Red Hat Data Grid 8, Red Hat Decision Manager 7, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, … · no fix planned: Red Hat JBoss Enterprise Application Platform 6, Migration Toolkit for Applications 6, Red Hat Data Grid 8, Red Hat Fuse 7, … · updated 2026-09-11 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6717.json)
