Improper authorization in Keycloak - CVE-2023-6544

 

Improper authorization in Keycloak - CVE-2023-6544

Published: April 17, 2024


Vulnerability identifier: #VU88793
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-6544
CWE-ID: CWE-285
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain unauthorized access to the application.

The vulnerability exists due to a permissive regular expression hard-coded for filtering allowed hosts to register a dynamic client within the org.keycloak.services.clientregistration package. A remote attacker with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized.


Affected software

Keycloak
Red Hat Single Sign-On
rh-sso7-keycloak (Red Hat package)

How to mitigate CVE-2023-6544

Install updates from vendor's website.

Keycloak - addressed in versions 22.0.10, 24.0.3
Red Hat Single Sign-On - update to 7.6.8
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.13-1.redhat_00001.1.el7sso, 18.0.13-1.redhat_00001.1.el8sso, 18.0.13-1.redhat_00001.1.el9sso

External References

Related Security Bulletins