/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2023-6291

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2023-6291

Severity

7.1

High

CVSS V3

Description

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing