Executive brief
Keycloak, an open-source identity and access management solution, is vulnerable to a log injection flaw during the security key (WebAuthn) login process. An attacker can provide malicious input that is recorded into the system logs without proper sanitization. This could allow an attacker to forge log entries, potentially misleading administrators or interfering with security monitoring and auditing.
Technical details
A log injection vulnerability (CWE-117) exists in Keycloak's WebAuthn implementation. When a user attempts to register or authenticate using a security key, errors generated in the browser client are written into a form and sent back to the Keycloak server. The server then logs these error messages without sufficient escaping or neutralization. A remote, unauthenticated attacker can manipulate these error strings to inject arbitrary content into the server logs. This can be used to spoof log entries or bypass log-based security controls. The issue is patched in versions 22.0.9 and 23.0.5.
Affected products
- Keycloak keycloak-services < 22.0.9, >= 23.0.0, < 23.0.5
Timeline
- 2024-04-17: disclosed
- 2024-04-17: advisory
- 2024-04-17: patched