CVE-2024-1132
published 2024-04-17CVE-2024-1132: A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious…
PriorityP345high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
1.55%
72.4th percentile
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_middleware_text-only_advisories | — | — |
| redhat | keycloak | >= 21.1.0 < 22.0.10 | 22.0.10 |
| redhat | keycloak | >= 23.0.0 < 24.0.3 | 24.0.3 |
| redhat | migration_toolkit_for_applications | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_ibm_z | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak path traversal vulnerability in redirection validation
ghsa·2024-04-17
CVE-2024-1132 [HIGH] CWE-22 Keycloak path traversal vulnerability in redirection validation
Keycloak path traversal vulnerability in redirection validation
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
#### Acknowledgements:
Special thanks to Axel Flamcourt for reporting this issue and helping us improve our project.
OSV
Keycloak path traversal vulnerability in redirection validation
osv·2024-04-17
CVE-2024-1132 [HIGH] Keycloak path traversal vulnerability in redirection validation
Keycloak path traversal vulnerability in redirection validation
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
#### Acknowledgements:
Special thanks to Axel Flamcourt for reporting this issue and helping us improve our project.
Red Hat
keycloak: path transversal in redirection validation
vendor_redhat·2024-04-16·CVSS 8.1
CVE-2024-1132 [HIGH] CWE-22 keycloak: path transversal in redirection validation
keycloak: path transversal in redirection validation
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:1860https://access.redhat.com/errata/RHSA-2024:1861https://access.redhat.com/errata/RHSA-2024:1862https://access.redhat.com/errata/RHSA-2024:1864https://access.redhat.com/errata/RHSA-2024:1866https://access.redhat.com/errata/RHSA-2024:1867https://access.redhat.com/errata/RHSA-2024:1868https://access.redhat.com/errata/RHSA-2024:2945https://access.redhat.com/errata/RHSA-2024:3752https://access.redhat.com/errata/RHSA-2024:3762https://access.redhat.com/errata/RHSA-2024:3919https://access.redhat.com/errata/RHSA-2024:3989https://access.redhat.com/security/cve/CVE-2024-1132https://bugzilla.redhat.com/show_bug.cgi?id=2262117https://access.redhat.com/errata/RHSA-2024:1860https://access.redhat.com/errata/RHSA-2024:1861https://access.redhat.com/errata/RHSA-2024:1862https://access.redhat.com/errata/RHSA-2024:1864https://access.redhat.com/errata/RHSA-2024:1866https://access.redhat.com/errata/RHSA-2024:1867https://access.redhat.com/errata/RHSA-2024:1868https://access.redhat.com/errata/RHSA-2024:2945https://access.redhat.com/errata/RHSA-2024:3752https://access.redhat.com/errata/RHSA-2024:3762https://access.redhat.com/errata/RHSA-2024:3919https://access.redhat.com/errata/RHSA-2024:3989https://access.redhat.com/security/cve/CVE-2024-1132https://bugzilla.redhat.com/show_bug.cgi?id=2262117
2024-04-17
Published