A log injection flaw was found in Keycloak. A text string may be injected through the authentication form when using the WebAuthn authentication mode. This issue may have a minor impact to the logs integrity.
rh-sso-7/sso7 Rocky
Fixed in: rhel8-operator@sha256:bc38682492e8166dca7a08d0eae81469270b5f979ff80f075bc63183126098c0_amd64 RHSA-2024:1865 Fixed in: rhel8-operator@sha256:990daa5745e5c3ba9da0087a0198de272027794949b8c5f45b86023702bfe8a0_ppc64le RHSA-2024:1865 Fixed in: rhel8-operator@sha256:586edd67e9b88b7f11bcec01308ef66aa20f7fd7307b821c1e6da5dbdee0786a_s390x RHSA-2024:1865 rh-sso-7/sso7 Red Hat / RHEL
Fixed in: rhel8-operator@sha256:586edd67e9b88b7f11bcec01308ef66aa20f7fd7307b821c1e6da5dbdee0786a_s390x RHSA-2024:1865 Fixed in: rhel8-operator@sha256:bc38682492e8166dca7a08d0eae81469270b5f979ff80f075bc63183126098c0_amd64 RHSA-2024:1865 Fixed in: rhel8-operator@sha256:990daa5745e5c3ba9da0087a0198de272027794949b8c5f45b86023702bfe8a0_ppc64le RHSA-2024:1865 rh-sso-7/sso7-rhel8 Red Hat / RHEL
Fixed in: operator-bundle@sha256:81208c494048b526ff577b0c9673f4e310e84627671d2da7ac072aa11292aedc_amd64 RHSA-2024:1865 Fixed in: init-container@sha256:f02e961e0c796ac8b65de30a5c364c63337003ba9d2b05b7041565cf3bd9d8c0_ppc64le RHSA-2024:1865 Fixed in: init-container@sha256:7c11cf4ea78020a3fba69c85e56c1c1eed08af61e7215dae5dcf7425f341b79d_amd64 RHSA-2024:1865 Fixed in: init-container@sha256:d89710eaa9b45dc180c311bd020255759383b0eb07826265e4ba810c6a047196_s390x RHSA-2024:1865 rh-sso-7/sso7-rhel8 Rocky
Fixed in: operator-bundle@sha256:81208c494048b526ff577b0c9673f4e310e84627671d2da7ac072aa11292aedc_amd64 RHSA-2024:1865 Fixed in: init-container@sha256:f02e961e0c796ac8b65de30a5c364c63337003ba9d2b05b7041565cf3bd9d8c0_ppc64le RHSA-2024:1865 Fixed in: init-container@sha256:7c11cf4ea78020a3fba69c85e56c1c1eed08af61e7215dae5dcf7425f341b79d_amd64 RHSA-2024:1865 Fixed in: init-container@sha256:d89710eaa9b45dc180c311bd020255759383b0eb07826265e4ba810c6a047196_s390x RHSA-2024:1865 rh-sso-7/sso76 Red Hat / RHEL
Fixed in: openshift-rhel8@sha256:2a21973655961ae87984bf1b76843419680fb0228fa0084c5bf8c696058bbc8d_ppc64le RHSA-2024:0801 Fixed in: openshift-rhel8@sha256:1f842e8f262ece6cd98941fd29562251e19479eb4f4ba7cbd8e9a3bfa79325f0_s390x RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:1909db8bc47fdb4f6512e08fb21ec1457f64fa0abf8edf2530f5bf5a494d9b6d_amd64 RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:b666f093f22ef27811114cca95c20aed890d4f3342116ab990d084cb2627d8cf_ppc64le RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:23d03851f0946e0ce058bfeeb458112e752b6b0dd8ebca078dc41b8e94c8e995_s390x RHSA-2024:0801 Fixed in: openshift-rhel8@sha256:1cde6dbbee3aa25be767953c45670d4c2592d61a7af776e7e0d0d1b08a1d23ab_amd64 RHSA-2024:0801 rh-sso-7/sso76 Rocky
Fixed in: openshift-rhel8@sha256:1cde6dbbee3aa25be767953c45670d4c2592d61a7af776e7e0d0d1b08a1d23ab_amd64 RHSA-2024:0801 Fixed in: openshift-rhel8@sha256:2a21973655961ae87984bf1b76843419680fb0228fa0084c5bf8c696058bbc8d_ppc64le RHSA-2024:0801 Fixed in: openshift-rhel8@sha256:1f842e8f262ece6cd98941fd29562251e19479eb4f4ba7cbd8e9a3bfa79325f0_s390x RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:1909db8bc47fdb4f6512e08fb21ec1457f64fa0abf8edf2530f5bf5a494d9b6d_amd64 RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:b666f093f22ef27811114cca95c20aed890d4f3342116ab990d084cb2627d8cf_ppc64le RHSA-2024:1864 Fixed in: openshift-rhel8@sha256:23d03851f0946e0ce058bfeeb458112e752b6b0dd8ebca078dc41b8e94c8e995_s390x RHSA-2024:0801 rh-sso7-keycloak Red Hat / RHEL
rh-sso7-keycloak-server Rocky
rh-sso7-keycloak-server Red Hat / RHEL
rhbk/keycloak Red Hat / RHEL
Fixed in: rhel9-operator@sha256:1f5fe6756a3767d1ca8cf3f79c9c14054012f73977602af5c1fc6c5e224fac52_ppc64le RHSA-2024:1867 Fixed in: rhel9@sha256:3787bdf294019d8a0f57f7d7e11da98522205de2625c7f287a1d00e11a5b2d83_ppc64le RHSA-2024:1867 Fixed in: rhel9-operator@sha256:06aa39709dbbd870a14be493bdd452243f700d2910072044ea0d7f8e4abe50b2_amd64 RHSA-2024:1867 Fixed in: operator-bundle@sha256:a47cee9b95ed78d7895c2582772abe3ccf239259ee3fbc2d7df8594450dc32f9_amd64 RHSA-2024:1867 Fixed in: rhel9@sha256:a462539eeff9638d642f13eb2dbc04a47cc39198a7f52d8b6eb07e1e14d783fd_amd64 RHSA-2024:1867 Fixed in: rhel9-operator@sha256:be417b344db10adf963d1f64c94e2d214e205489e03395dc508074d783e6422e_s390x RHSA-2024:1867 Fixed in: rhel9@sha256:20d135d4d422505497c9aa85afb6acb2d9378191358632700e1ce0f259507583_s390x RHSA-2024:1867 rhbk/keycloak Rocky
Fixed in: rhel9-operator@sha256:06aa39709dbbd870a14be493bdd452243f700d2910072044ea0d7f8e4abe50b2_amd64 RHSA-2024:1867 Fixed in: operator-bundle@sha256:a47cee9b95ed78d7895c2582772abe3ccf239259ee3fbc2d7df8594450dc32f9_amd64 RHSA-2024:1867 Fixed in: rhel9@sha256:a462539eeff9638d642f13eb2dbc04a47cc39198a7f52d8b6eb07e1e14d783fd_amd64 RHSA-2024:1867 Fixed in: rhel9-operator@sha256:be417b344db10adf963d1f64c94e2d214e205489e03395dc508074d783e6422e_s390x RHSA-2024:1867 Fixed in: rhel9@sha256:20d135d4d422505497c9aa85afb6acb2d9378191358632700e1ce0f259507583_s390x RHSA-2024:1867 Fixed in: rhel9-operator@sha256:1f5fe6756a3767d1ca8cf3f79c9c14054012f73977602af5c1fc6c5e224fac52_ppc64le RHSA-2024:1867 Fixed in: rhel9@sha256:3787bdf294019d8a0f57f7d7e11da98522205de2625c7f287a1d00e11a5b2d83_ppc64le RHSA-2024:1867 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality None
Integrity Low
Availability None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
1.01% probability of exploitation in 30 days
59th percentile
Moderate risk: more likely to be exploited than 59% of all known CVEs.
Other CWE-117 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2023-6484 Markdown
[](https://tridentstack.com/cve/CVE-2023-6484)HTML
<a href="https://tridentstack.com/cve/CVE-2023-6484"><img src="https://tridentstack.com/cve/badge/CVE-2023-6484.svg" alt="CVE-2023-6484"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2026-06-26.