Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) (CWE-75)
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
RedHat CVE advisory released a security advisory (CVE-2023-6134).
Feedly found the first article mentioning CVE-2023-6134. See article
NVD published the first details for CVE-2023-6134
EPSS Score was set to: 0.04% (Percentile: 10.6%)
The vulnerability CVE-2023-6134 in Keycloak allows for cross-site scripting (XSS) attacks through wildcard redirect URIs. It has a fix in Keycloak 23.0.3, but the patch only partially addresses the issue, enabling bypassing of redirect URI restrictions. There is no information provided regarding the criticality, exploitation in the wild, proof-of-concept exploits, mitigations, detections, patches, or downstream impacts to other vendors or technology. See article