Improper Output Neutralization for Logs
CVE-2023-6484
Summary
A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuth authentication mode. This issue may have a minor impact on log integrity. This vulnerability affects versions prior to 22.0.9, and 23.0.x prior to 23.0.5.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-117 - Improper Output Neutralization for Logs
The software does not neutralize or incorrectly neutralizes output that is written to logs.
References
Advisory Timeline
- Published