Files
CVEs-PoC/2023/CVE-2023-6544.md
T
2025-09-29 21:09:30 +02:00

1.8 KiB

CVE-2023-6544

Description

A flaw was found in the Keycloak package. This issue occurs due to a permissive regular expression hardcoded for filtering which allows hosts to register a dynamic client. A malicious user with enough information about the environment could jeopardize an environment with this specific Dynamic Client Registration and TrustedDomain configuration previously unauthorized.

POC

Reference

No PoCs from references.

Github