Vulnerable Redirect URI Validation Results in Open Redirect
Moderate severity
GitHub Reviewed
Published
Oct 14, 2024
in
keycloak/keycloak
•
Updated Oct 14, 2024
Package
Affected versions
<= 22.0.12
>= 23.0.0, <= 24.0.7
>= 25.0.0, <= 25.0.5
Patched versions
22.0.13
24.0.8
25.0.6
Description
Published to the GitHub Advisory Database
Oct 14, 2024
Reviewed
Oct 14, 2024
Last updated
Oct 14, 2024
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost/ or http://127.0.0.1/, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
References