CVE-2023-6291
Aliases:GHSA-mpwq-j3xf-7m5w
Advisory lineage Upstream: 0 Downstream: 6
Modified
Published: 26 Jan 2024, 14:23
Last modified:11 Nov 2025, 16:12
Vulnerability Summary
Overall Risk (default)
medium
28/100 CVSS Score
7.1 HIGH
v3.1 (cve.org)
EPSS Score
0.18% LOW
0% probability -0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Jan 2024, 14:23
Published
Vulnerability first disclosed
11 Nov 2025, 16:12
Last Modified
Vulnerability information updated
Description
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
CVSS Metrics
- v3.1•HIGH•Score: 7.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
EPSS Trends
Current EPSS score: 0.18%• Percentile: 39%
Techniques & Countermeasures
- CWE-601•URL Redirection to Untrusted Site ('Open Redirect')
The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.
Affected Systems
- org.keycloak•keycloak-services
< 23.0.3
- redhat•keycloak
< 22.0.7
- redhat•migration_toolkit_for_applications
6.0 | 7.0
- redhat•openshift_container_platform
4.11 | 4.12
- redhat•openshift_container_platform_for_ibm_z
4.9 | 4.10
- redhat•openshift_container_platform_for_linuxone
4.9 | 4.10
- redhat•openshift_container_platform_for_power
4.9 | 4.10
- redhat•single_sign-on
na | 7.6
References (18)
- https://access.redhat.com/errata/RHSA-2023:7854
- https://access.redhat.com/errata/RHSA-2023:7855
- https://access.redhat.com/errata/RHSA-2023:7856
- https://access.redhat.com/errata/RHSA-2023:7857
- https://access.redhat.com/errata/RHSA-2023:7858
- https://access.redhat.com/errata/RHSA-2023:7860
- https://access.redhat.com/errata/RHSA-2023:7861
- https://access.redhat.com/errata/RHSA-2024:0798
- https://access.redhat.com/errata/RHSA-2024:0799
- https://access.redhat.com/errata/RHSA-2024:0800
- https://access.redhat.com/errata/RHSA-2024:0801
- https://access.redhat.com/errata/RHSA-2024:0804
- https://access.redhat.com/security/cve/CVE-2023-6291
- https://bugzilla.redhat.com/show_bug.cgi?id=2251407
- https://github.com/keycloak/keycloak/security/advisories/GHSA-mpwq-j3xf-7m5w
- https://nvd.nist.gov/vuln/detail/CVE-2023-6291
- https://github.com/keycloak/keycloak/commit/b2e91105315ccf2c1df549b4f6c5948322cbfd1b
- https://github.com/keycloak/keycloak