MEDIUM 5.3
GHSA-j628-q885-8gr5
Keycloak vulnerable to log Injection during WebAuthn authentication or registration
Quick fix
GHSA-j628-q885-8gr5 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.
# pom.xml: bump <version>22.0.9</version> for org.keycloak:keycloak-services Details
A flaw was found in keycloak 22.0.5. Errors in browser client during setup/auth with "Security Key login" (WebAuthn) are written into the form, send to Keycloak and logged without escaping allowing log injection.
Acknowledgements: Special thanks toTheresa Henze for reporting this issue and helping us improve our security.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.keycloak:keycloak-services
Introduced in:
0 Fixed in: 22.0.9 Fix
# pom.xml: bump <version>22.0.9</version> for org.keycloak:keycloak-services Maven / org.keycloak:keycloak-services
Introduced in:
23.0.0 Fixed in: 23.0.5 Fix
# pom.xml: bump <version>23.0.5</version> for org.keycloak:keycloak-services References
- https://github.com/keycloak/keycloak/security/advisories/GHSA-j628-q885-8gr5 [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-6484 [ADVISORY]
- https://github.com/keycloak/keycloak/issues/25078 [WEB]
- https://github.com/keycloak/keycloak/commit/f9049565a9a228faa08138b9269d66d3de6c7e9a [WEB]
- https://github.com/keycloak/keycloak/commit/110f64a8146d0817252f90cf4b5e6a62aa897aff [WEB]
- https://github.com/keycloak/keycloak [PACKAGE]
- https://github.com/advisories/GHSA-j628-q885-8gr5 [ADVISORY]
- https://bugzilla.redhat.com/show_bug.cgi?id=2248423 [WEB]
- https://access.redhat.com/security/cve/CVE-2023-6484 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1868 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1867 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1866 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1865 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1864 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1862 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1861 [WEB]
- https://access.redhat.com/errata/RHSA-2024:1860 [WEB]
- https://access.redhat.com/errata/RHSA-2024:0804 [WEB]
- https://access.redhat.com/errata/RHSA-2024:0801 [WEB]
- https://access.redhat.com/errata/RHSA-2024:0800 [WEB]
- https://access.redhat.com/errata/RHSA-2024:0799 [WEB]
- https://access.redhat.com/errata/RHSA-2024:0798 [WEB]