Количество 4
Количество 4
CVE-2024-1132
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
CVE-2024-1132
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
CVE-2024-1132
A flaw was found in Keycloak, where it does not properly validate URLs ...
GHSA-72vp-xfrc-42xm
Keycloak path traversal vulnerability in redirection validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-1132 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
CVE-2024-1132 A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL. | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
CVE-2024-1132 A flaw was found in Keycloak, where it does not properly validate URLs ... | CVSS3: 8.1 | 0% Низкий | почти 2 года назад | |
GHSA-72vp-xfrc-42xm Keycloak path traversal vulnerability in redirection validation | CVSS3: 8.1 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу