Skip to content

Authorization Bypass

Moderate
abstractj published GHSA-46c8-635v-68r2 Apr 17, 2024

Package

maven org.keycloak.services.clientregistration (Maven)

Affected versions

< 22.0.10, < 24.0.3

Patched versions

22.0.10, 24.0.3

Description

Due to a permissive regular expression hardcoded for filtering allowed hosts to register a dynamic client, a malicious user with enough information about the environment could benefit and jeopardize an environment with this specific Dynamic Client Registration with TrustedDomain configuration previously unauthorized.

Acknowledgements:

Special thanks to Bastian Kanbach for reporting this issue and helping us improve our security.

Severity

Moderate

CVE ID

CVE-2023-6544