GPU VulnDB

Database/Control plane, storage & DevOps

Keycloak: Wildcard in the JARM form_post.jwt response mode

CVE-2023-6927Control plane, storage & DevOpscurated

Impact

Wildcard in the JARM form_post.jwt response mode -> steal authorization codes and tokens (bypasses the CVE-2023-6134 fix)

Who can reach it

Network (remote)

What to do

Control-plane: upgrade + remove wildcards from client redirect URIs

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.