Skip to main content

Improper Output Neutralization for Logs

CVE-2023-6484

Severity Medium
Score 5.3/10

Summary

A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuth authentication mode. This issue may have a minor impact on log integrity. This vulnerability affects versions prior to 22.0.9, and 23.0.x prior to 23.0.5.

  • LOW
  • NETWORK
  • LOW
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • NONE

CWE-117 - Improper Output Neutralization for Logs

The software does not neutralize or incorrectly neutralizes output that is written to logs.

Advisory Timeline

  • Published