Keycloak Open Redirect vulnerability
Moderate severity
GitHub Reviewed
Published
Dec 19, 2023
to the GitHub Advisory Database
•
Updated Jan 9, 2024
Description
Published by the National Vulnerability Database
Dec 18, 2023
Published to the GitHub Advisory Database
Dec 19, 2023
Reviewed
Dec 19, 2023
Last updated
Jan 9, 2024
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
References