CVE-2023-6544

MEDIUM5.4EPSS 1.3%

Keycloak Authorization Bypass vulnerability

Published: 4/17/2024Modified: 2/4/2026

Description

Due to a permissive regular expression hardcoded for filtering allowed hosts to register a dynamic client, a malicious user with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized. #### Acknowledgements: Special thanks to Bastian Kanbach for reporting this issue and helping us improve our security.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

References (12)

CVE-2023-6544 — Keycloak Authorization Bypass vulnerability · VulnScope