CVE-2023-6544: Red Hat Build Of Keycloak 22
Medium severity, CVSS 5.4. EPSS: 1.1% chance of exploitation in the next 30 days.
A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.
Affected products
- Red Hat Red Hat Build Of Keycloak 22: before 22.0.10-1 (fixed in 22.0.10-1); before 22-13 (fixed in 22-13); before 22-16 (fixed in 22-16)
- Red Hat Red Hat Build Of Keycloak 22.0.10
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 7: before 0:18.0.13-1.redhat_00001.1.el7sso (fixed in 0:18.0.13-1.redhat_00001.1.el7sso)
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 8: before 0:18.0.13-1.redhat_00001.1.el8sso (fixed in 0:18.0.13-1.redhat_00001.1.el8sso)
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 9: before 0:18.0.13-1.redhat_00001.1.el9sso (fixed in 0:18.0.13-1.redhat_00001.1.el9sso)
- Red Hat Rhel-8 Based Middleware Containers: before 7.6-46 (fixed in 7.6-46)
- Red Hat Rhsso 7.6.8
Published 2024-04-25. Last modified 2026-06-17.