CVE Published: 25/04/2024 |
CVE Updated: 24/11/2024 |
CVE Year: 2023 Source: redhat |
Vendor: |
Product: Status : PUBLISHED
CVE-2023-6544 Description
A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.