CVE-2023-6717
Executive Summary
Keycloak SAML client registration flaw permits an administrator or privileged client to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs. When users submit SAML assertions, the injected script executes in the victim’s browser, enabling arbitrary code execution, credential theft, or session hijacking across realms. The vulnerability can be leveraged to compromise confidentiality, integrity, and availability of the entire Keycloak deployment.
Authoritative CVE Metadata - CVSS Base Score: 6.0 (MEDIUM) - Published: 2024-04-25T16:15:10.653 - Last Modified: 2026-09-11T02:18:31.073
Original Description: A flaw was found in the SAML client registration in Keycloak that could allow an administrator to register malicious JavaScript URIs as Assertion Consumer Service POST Binding URLs (ACS), posing a Cross-Site Scripting (XSS) risk. This issue may allow a malicious admin in one realm or a client with registration access to target users in different realms or applications, executing arbitrary JavaScript in their contexts upon form submission. This can enable unauthorized access and harmful actions, compromising the confidentiality, integrity, and availability of the complete KC instance.
"Into each life rain must fall but rain can be the giver of life and it is all in your attitude that makes rain produce sunshine."
— Byron Pulsifer