Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8gr-xwp4-r9f7

Опубликовано: 14 окт. 2024
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost/ or http://127.0.0.1/, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

<= 22.0.12

22.0.13

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 23.0.0, <= 24.0.7

24.0.8

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 25.0.0, <= 25.0.5

25.0.6

EPSS

Процентиль: 87%
0.0339
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 6.1
redhat
больше 1 года назад

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVSS3: 6.1
nvd
больше 1 года назад

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVSS3: 6.1
debian
больше 1 года назад

A misconfiguration flaw was found in Keycloak. This issue can allow an ...

EPSS

Процентиль: 87%
0.0339
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601