← Back to CVE List

CVE-2023-6291

Published: 2024-01-26T15:15Z
Last Modified: 2024-11-21T08:43Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt