CVE-2024-1132
—CVSS 3.1
8.1 high
EPSS
2%p74
Published
()
Modified
Description
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
- Vendors
- redhat
- Products
- build of keycloak, jboss middleware text-only advisories, keycloak, migration toolkit for applications, migration toolkit for runtimes, openshift container platform, openshift container platform for ibm z, openshift container platform for linuxone, openshift container platform for power, single sign-on
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.