REDHAT-BUG-2248423: Low severity keycloak vulnerability
Published Nov 7, 2023
·Updated
A flaw was found in keycloak 22.0.5. Errors in browser client during setup/auth with "Security Key login" (WebAuthn) are written into the form, send to Keycloak and logged without escaping allowing log injection.
Affected Software
1 affected component
Red Hat Keycloak
Event History
Nov 7, 2023
Data Sourced
via Red Hat·12:47 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2248423?
The severity of REDHAT-BUG-2248423 is considered significant due to the potential for log injection attacks.
2
How can I fix REDHAT-BUG-2248423?
To fix REDHAT-BUG-2248423, it's recommended to update to the latest version of Keycloak that addresses this vulnerability.
3
What versions of Keycloak are affected by REDHAT-BUG-2248423?
REDHAT-BUG-2248423 specifically affects Keycloak version 22.0.5.
4
What kind of vulnerability is REDHAT-BUG-2248423?
REDHAT-BUG-2248423 is a security vulnerability related to log injection due to improper escaping of errors in the browser client.
5
Is there a workaround for REDHAT-BUG-2248423?
There is no known workaround for REDHAT-BUG-2248423 other than upgrading to the patched version.