A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
Link | Tags |
---|---|
https://access.redhat.com/errata/RHSA-2024:0798 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:0799 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:0800 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:0801 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:0804 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1860 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1861 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1862 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1864 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1865 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1866 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1867 | vendor advisory |
https://access.redhat.com/errata/RHSA-2024:1868 | vendor advisory |
https://access.redhat.com/security/cve/CVE-2023-6484 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2248423 | issue tracking |