MEDIUM4.6
GHSA-9vm7-v8wj-3fqw
keycloak-core: open redirect via "form_post.jwt" JARM response mode
Quick fix
GHSA-9vm7-v8wj-3fqw — org.keycloak:keycloak-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>23.0.4</version> for org.keycloak:keycloak-coreDetails
An incomplete fix was found in Keycloak Core patch. An attacker can steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt". It is observed that changing the response_mode parameter in the original proof of concept from "form_post" to "form_post.jwt" can bypass the security patch implemented to address CVE-2023-6134.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-core
Introduced in:
0Fixed in: 23.0.4Fix
# pom.xml: bump <version>23.0.4</version> for org.keycloak:keycloak-coreReferences
- https://github.com/keycloak/keycloak/security/advisories/GHSA-9vm7-v8wj-3fqw[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-6927[ADVISORY]
- https://access.redhat.com/errata/RHSA-2024:0094[WEB]
- https://access.redhat.com/errata/RHSA-2024:0095[WEB]
- https://access.redhat.com/errata/RHSA-2024:0096[WEB]
- https://access.redhat.com/errata/RHSA-2024:0097[WEB]
- https://access.redhat.com/errata/RHSA-2024:0098[WEB]
- https://access.redhat.com/errata/RHSA-2024:0100[WEB]
- https://access.redhat.com/errata/RHSA-2024:0101[WEB]
- https://access.redhat.com/security/cve/CVE-2023-6927[WEB]
- https://bugzilla.redhat.com/show_bug.cgi?id=2255027[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]