ZeroHour

CVE-2024-1132

CVSS 3.1
8.1 high
EPSS
2%p74
Published
()
Modified
Description

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

Vendors
redhat
Products
build of keycloak, jboss middleware text-only advisories, keycloak, migration toolkit for applications, migration toolkit for runtimes, openshift container platform, openshift container platform for ibm z, openshift container platform for linuxone, openshift container platform for power, single sign-on
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.