A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
References
Configurations
History
No history.
Information
Published : 2023-12-18 23:15
Updated : 2024-02-14 03:15
NVD link : CVE-2023-6927
Mitre link : CVE-2023-6927
CVE.ORG link : CVE-2023-6927
JSON object : View
Products Affected
redhat
- single_sign-on
- keycloak
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')