« Volver al listado

CVE-2023-6544

Estado: AplazadaMedia (5.4)—

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6544",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-6544",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-04-25T19:19:09.097776Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert@redhat.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "versions": [
            {
              "status": "affected",
              "version": "22.0.0",
              "lessThan": "22.0.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "23.0.0",
              "lessThan": "24.0.3",
              "versionType": "semver"
            }
          ],
          "packageName": "org.keycloak:keycloak-services",
          "collectionURL": "https://github.com/keycloak/keycloak",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22.0.10-1",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-operator-bundle",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-13",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22",
          "versions": [
            {
              "status": "unaffected",
              "version": "22-16",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rhbk/keycloak-rhel9-operator",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:build_keycloak:22"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat build of Keycloak 22.0.10",
          "packageName": "keycloak-core",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7.6::el7"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Single Sign-On 7.6 for RHEL 7",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:18.0.13-1.redhat_00001.1.el7sso",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rh-sso7-keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7.6::el8"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Single Sign-On 7.6 for RHEL 8",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:18.0.13-1.redhat_00001.1.el8sso",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rh-sso7-keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7.6::el9"
          ],
          "vendor": "Red Hat",
          "product": "Red Hat Single Sign-On 7.6 for RHEL 9",
          "versions": [
            {
              "status": "unaffected",
              "version": "0:18.0.13-1.redhat_00001.1.el9sso",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rh-sso7-keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:rhosemc:1.0::el8"
          ],
          "vendor": "Red Hat",
          "product": "RHEL-8 based Middleware Containers",
          "versions": [
            {
              "status": "unaffected",
              "version": "7.6-46",
              "lessThan": "*",
              "versionType": "rpm"
            }
          ],
          "packageName": "rh-sso-7/sso76-openshift-rhel8",
          "collectionURL": "https://catalog.redhat.com/software/containers/",
          "defaultStatus": "affected"
        },
        {
          "cpes": [
            "cpe:/a:redhat:red_hat_single_sign_on:7.6"
          ],
          "vendor": "Red Hat",
          "product": "RHSSO 7.6.8",
          "packageName": "rh-sso7-keycloak",
          "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-04-25T16:15:10.097",
  "references": [
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1860",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1861",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1862",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1864",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1866",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1867",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1868",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-6544",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253116",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1860",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1861",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1862",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1864",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1866",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1867",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/errata/RHSA-2024:1868",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://access.redhat.com/security/cve/CVE-2023-6544",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253116",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secalert@redhat.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-625"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized."
    },
    {
      "lang": "es",
      "value": "Se encontró una falla en el paquete Keycloak. Este problema se produce debido a una expresión regular permisiva codificada para el filtrado que permite a los hosts registrar un cliente dinámico. Un usuario malintencionado con suficiente información sobre el entorno podría poner en peligro un entorno con este registro dinámico de cliente específico y esta configuración de TrustedDomain previamente no autorizada."
    }
  ],
  "lastModified": "2026-06-17T06:50:57.267",
  "sourceIdentifier": "secalert@redhat.com"
}