A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.
References
Configurations
No configuration.
History
25 Apr 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-04-25 16:15
Updated : 2024-04-25 17:24
NVD link : CVE-2023-6544
Mitre link : CVE-2023-6544
CVE.ORG link : CVE-2023-6544
JSON object : View
Products Affected
No product.
CWE
CWE-625
Permissive Regular Expression