[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249622

 
 

909

 
 

195549

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2023-6544Date: (C)2024-04-25   (M)2024-04-26


A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

Reference:
RHBZ#2253116
RHSA-2024:1860
RHSA-2024:1861
RHSA-2024:1862
RHSA-2024:1864
RHSA-2024:1866
RHSA-2024:1867
RHSA-2024:1868
https://access.redhat.com/security/cve/CVE-2023-6544

CWE    1
CWE-625
XCCDF    1

© SecPod Technologies