CVE-2023-6291: Red Hat Keycloak

High severity, CVSS 7.1. EPSS: 1% chance of exploitation in the next 30 days.

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.

Affected products

  • Red Hat Keycloak: before 22.0.7 (fixed in 22.0.7)
  • Red Hat Migration Toolkit For Applications: version 6.0 only; version 7.0 only
  • Red Hat Openshift Container Platform: version 4.11 only; version 4.12 only
  • Red Hat Openshift Container Platform For IBM Z: version 4.9 only; version 4.10 only
  • Red Hat Openshift Container Platform For Linuxone: version 4.9 only; version 4.10 only
  • Red Hat Openshift Container Platform For Power: version 4.9 only; version 4.10 only
  • Red Hat Single Sign-On: affected versions not specified; version 7.6 only

Published 2024-01-26. Last modified 2026-09-22.