CVE-2023-6484: Red Hat Build Of Keycloak 22

Medium severity, CVSS 5.3. EPSS: 1% chance of exploitation in the next 30 days.

A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.

Affected products

  • Red Hat Red Hat Build Of Keycloak 22: before 22.0.10-1 (fixed in 22.0.10-1); before 22-13 (fixed in 22-13); before 22-16 (fixed in 22-16)
  • Red Hat Red Hat Build Of Keycloak 22.0.10
  • Red Hat Red Hat Single Sign-On 7
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 7: before 0:18.0.12-1.redhat_00001.1.el7sso (fixed in 0:18.0.12-1.redhat_00001.1.el7sso); before 0:18.0.13-1.redhat_00001.1.el7sso (fixed in 0:18.0.13-1.redhat_00001.1.el7sso)
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 8: before 0:18.0.12-1.redhat_00001.1.el8sso (fixed in 0:18.0.12-1.redhat_00001.1.el8sso); before 0:18.0.13-1.redhat_00001.1.el8sso (fixed in 0:18.0.13-1.redhat_00001.1.el8sso)
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 9: before 0:18.0.12-1.redhat_00001.1.el9sso (fixed in 0:18.0.12-1.redhat_00001.1.el9sso); before 0:18.0.13-1.redhat_00001.1.el9sso (fixed in 0:18.0.13-1.redhat_00001.1.el9sso)
  • Red Hat Rhel-8 Based Middleware Containers: before 7.6-41 (fixed in 7.6-41); before 7.6-46 (fixed in 7.6-46); before 7.6-16 (fixed in 7.6-16); before 7.6-18 (fixed in 7.6-18); before 7.6.8-2 (fixed in 7.6.8-2)
  • Red Hat Rhsso 7.6.8

Published 2024-04-25. Last modified 2026-06-26.