ZeroHour

CVE-2024-8883

CVSS 3.1
6.1 medium
EPSS
2%p80
Published
()
Modified
Description

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

Vendors
redhat
Products
build of keycloak, openshift container platform, openshift container platform for ibm z, openshift container platform for linuxone, openshift container platform for power, single sign-on
Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.