Описание
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the client_session_host parameter during refresh token requests. This occurs when a Keycloak client is configured to use the backchannel.logout.url with the application.session.host placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
Отчет
This flaw allows an authenticated attacker to perform Server-Side Request Forgery (SSRF) by manipulating the client_session_host parameter during refresh token requests. This vulnerability is exploitable when a Keycloak client is configured to use the backchannel.logout.url with the application.session.host placeholder, enabling the attacker to probe internal networks from the Keycloak server's context. Exploitation requires valid user credentials and a logout event.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | rhbk/keycloak-operator-bundle | Fix deferred | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9-operator | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-services | Fix deferred | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | keycloak-services | Fix deferred | ||
| Red Hat Single Sign-On 7 | keycloak-services | Fix deferred |
Показывать по
Дополнительная информация
Статус:
3.1 Low
CVSS3
Связанные уязвимости
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the attacker to make HTTP requests from the Keycloak server’s network context, potentially probing internal networks or internal APIs, leading to information disclosure.
A flaw was found in Keycloak. An authenticated attacker can perform Se ...
Keycloak Server-Side Request Forgery via OIDC token endpoint manipulation
3.1 Low
CVSS3