A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "7.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "4.10"
}
]
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-6134.json"