CVE-2023-6927 Information
Dec 22, 2023
cve
Description
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode orm_post.jwt\ which could be used to bypass the security patch implemented to address CVE-2023-6134.
Reference
https://access.redhat.com/security/cve/CVE-2023-6927 https://bugzilla.redhat.com/show_bug.cgi?id=2255027
Share on: