CVE-2023-6717
Java vulnerability analysis and mitigation

Overview

A vulnerability (CVE-2023-6717) was discovered in the SAML client registration functionality of Keycloak. The flaw was disclosed on April 25, 2024, affecting Keycloak's SAML client registration system. This vulnerability allows an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), creating a Cross-Site Scripting (XSS) risk (NVD, Red Hat CVE).

Technical details

The vulnerability stems from Keycloak's insufficient validation of SAML Assertion Consumer Service POST Binding URLs, which permits the registration of JavaScript URIs. When combined with HTML forms, this can lead to JavaScript code execution in the context of the embedding origin upon form submission. The vulnerability has been assigned a CVSS v3.1 base score of 6.0 (Medium) with the vector string CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:L, indicating network accessibility with high attack complexity, high privileges required, and user interaction needed (Red Hat CVE).

Impact

The vulnerability can enable a malicious admin in one realm or a client with registration access to target users in different realms or applications. By executing arbitrary JavaScript in their contexts upon form submission, attackers can potentially gain unauthorized access and perform harmful actions. This compromises the confidentiality, integrity, and availability of the complete Keycloak instance (NVD).

Exploitability

The vulnerability requires high privileges (administrator access or client registration permissions) and user interaction for successful exploitation. The attack complexity is considered high, as it involves crafting specific malicious JavaScript URIs and requires users to submit forms for the attack to be executed (Red Hat CVE).

Mitigation and workarounds

Red Hat has addressed this vulnerability in multiple products including Red Hat build of Keycloak 22.0.10, Red Hat Process Automation Manager 7.13.5, and Red Hat AMQ Broker 7.12.0. Updates are available through various security advisories including RHSA-2024:1867, RHSA-2024:1868, and RHSA-2024:2945 (Red Hat Advisory).

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-69205HIGH8.7
  • Java logoJava
  • org.http4s:http4s-ember-core_2.12
NoYesSep 15, 2026
CVE-2026-88975HIGH7.5
  • Java logoJava
  • org.http4s:http4s-ember-core_2.12
NoYesSep 15, 2026
CVE-2026-69218HIGH7.5
  • Java logoJava
  • org.http4s:http4s-ember-core_2.12
NoYesSep 15, 2026
CVE-2026-69215MEDIUM6.8
  • Java logoJava
  • org.http4s:http4s-client_2.12
NoYesSep 15, 2026
CVE-2026-69206MEDIUM5.9
  • Java logoJava
  • org.http4s:http4s-ember-core_2.12
NoYesSep 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management