Description
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-3189 | A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748. |
Github GHSA |
GHSA-cvg2-7c3j-g36j | Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri |
References
History
No history.
Subscriptions
Redhat
Subscribe
Build Keycloak
Subscribe
Enterprise Linux
Subscribe
Keycloak
Subscribe
Openshift Container Platform
Subscribe
Openshift Container Platform For Power
Subscribe
Openshift Container Platform Ibm Z Systems
Subscribe
Red Hat Single Sign On
Subscribe
Rhosemc
Subscribe
Single Sign-on
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-02-25T18:19:50.968Z
Reserved: 2023-11-14T18:50:13.535Z
Link: CVE-2023-6134
No data.
Status : Modified
Published: 2023-12-14T22:15:44.087
Modified: 2024-11-21T08:43:12.193
Link: CVE-2023-6134
OpenCVE Enrichment
No data.
EUVD
Github GHSA