A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enablin…
Medium CVSS 6.1
Summary
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://access.redhat.com/errata/RHSA-2024:10385
- https://access.redhat.com/errata/RHSA-2024:10386
- https://access.redhat.com/errata/RHSA-2024:6878 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6879 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6880 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6882 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6886 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6887 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6888 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6889 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6890 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:8823
- https://access.redhat.com/errata/RHSA-2024:8824
- https://access.redhat.com/errata/RHSA-2024:8826
- https://access.redhat.com/security/cve/CVE-2024-8883 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2312511 Issue Tracking
- https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/protocol/oidc/utils/RedirectUtils.java Product
Timeline
- nvd_ingest NVD