CVE-2018-14658
published 2018-11-13CVE-2018-14658: A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils…
PriorityP420medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.10%
62.0th percentile
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat | keycloak | — | — |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: Open Redirect in Login and Logout
vendor_redhat·2018-11-13·CVSS 6.1
CVE-2018-14658 [MEDIUM] CWE-601 keycloak: Open Redirect in Login and Logout
keycloak: Open Redirect in Login and Logout
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
Package: keycloak (Red Hat Fuse 7) - Will not fix
Package: keycloak (Red Hat Mobile Application Platform 4) - Out of support scope
GHSA
Keycloak Open Redirect
ghsa·2022-05-13
CVE-2018-14658 [MEDIUM] CWE-601 Keycloak Open Redirect
Keycloak Open Redirect
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in `org.keycloak.protocol.oidc.utils.RedirectUtils` before the redirect url is verified. This can lead to an Open Redirection attack
OSV
Keycloak Open Redirect
osv·2022-05-13
CVE-2018-14658 [MEDIUM] Keycloak Open Redirect
Keycloak Open Redirect
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in `org.keycloak.protocol.oidc.utils.RedirectUtils` before the redirect url is verified. This can lead to an Open Redirection attack
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:3592https://access.redhat.com/errata/RHSA-2018:3593https://access.redhat.com/errata/RHSA-2018:3595https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658https://access.redhat.com/errata/RHSA-2018:3592https://access.redhat.com/errata/RHSA-2018:3593https://access.redhat.com/errata/RHSA-2018:3595https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658
2018-11-13
Published