RHSA-2023:7861HighCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 22.0.7 images enhancement and security update

Published
December 14, 2023
Last Modified
August 4, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2023-6134 — keycloak: reflected XSS via wildcard in OIDC redirect_uri CVE-2023-6291 — keycloak: redirect_uri validation bypass

🎯 Affected products8

  • Red Hat build of Keycloak 22
  • rhbk/keycloak-operator-bundle@sha256:95af3ba537cf925f0359d54c7cd6d1dc360c9f109dcdd79322e9eb981c9b1ec6_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:96bdf3a2d1491a1cf26c0f8e46ff0b124d27f8ae67181b6e52faffc5cafd8837_s390x as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:b79c5a6857d87daedeb8bf90fd4df9f73a663c5dc1567a5855eeebc8776d8b04_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9-operator@sha256:c27cc8e7d7afc40125624c250be2cbefc9589645df6890bef6b601bbcfd0a9d7_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:ca08c57756107d6701bdc10590466a7ca7a42bf1bc7883e9df3d4b6b04800343_amd64 as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:cae4e2e48188b03a76a4e13e061e16cae7ee053bf32ec164ed140dce30c94cbf_ppc64le as a component of Red Hat build of Keycloak 22
  • rhbk/keycloak-rhel9@sha256:ff4d7fbeb78a227d9078acb131a0762f36df194f905f5c8f1434efe073355b92_s390x as a component of Red Hat build of Keycloak 22

✅ Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (5)