CVE-2024-8883
Keycloak: vulnerable redirect uri validation results in open redirec
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Produtos afetados
keycloak-servicesRed Hat · Red Hat Build of KeycloakRed Hat · Red Hat build of Keycloak 22Red Hat · Red Hat build of Keycloak 24Red Hat · Red Hat JBoss Enterprise Application Platform 8Red Hat · Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8Red Hat · Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9Red Hat · Red Hat Single Sign-On 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 8Red Hat · Red Hat Single Sign-On 7.6 for RHEL 9Red Hat · RHEL-8 based Middleware ContainersQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2024:10385https://access.redhat.com/errata/RHSA-2024:10386https://access.redhat.com/errata/RHSA-2024:6878https://access.redhat.com/errata/RHSA-2024:6879https://access.redhat.com/errata/RHSA-2024:6880https://access.redhat.com/errata/RHSA-2024:6882https://access.redhat.com/errata/RHSA-2024:6886https://access.redhat.com/errata/RHSA-2024:6887https://access.redhat.com/errata/RHSA-2024:6888https://access.redhat.com/errata/RHSA-2024:6889https://access.redhat.com/errata/RHSA-2024:6890https://access.redhat.com/errata/RHSA-2024:8823