CVE-2024-1132

CWE-22Path Traversal5 documents5 sources
Severity
8.1HIGH
EPSS
0.3%
top 44.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17

Description

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages5 packages

Also affects: Openshift Container Platform 4.11, 4.12, 4.10, 4.9

🔴Vulnerability Details

3
CVEList
Keycloak: path transversal in redirection validation2024-04-17
GHSA
Keycloak path traversal vulnerability in redirection validation2024-04-17
OSV
Keycloak path traversal vulnerability in redirection validation2024-04-17

📋Vendor Advisories

1
Red Hat
keycloak: path transversal in redirection validation2024-04-16