CVE-2023-6717 MEDIUM

CVE-2023-6717: Keycloak: xss via assertion consumer service url in saml post-binding flow

Vendor Red Hat
Product Red Hat AMQ Broker 7
Weakness CWE-79 · XSS
Published April 25, 2024
Last update June 2, 2026

CVSS base score

6.0/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L

What the vulnerability does

01Description

A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.

Key dates

02Disclosure timeline

April 25, 2024 CVE published
June 2, 2026 Record updated