CVE-2014-3652: Medium severity red hat keycloak vulnerability
Published Dec 15, 2019
·Updated
JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.
Affected Software
2 affected componentsFixes available
maven/org.keycloak:keycloak-services<1.1.0.Beta1
1.1.0.Beta1
redhat Keycloak=1.0.1
Remediation
Patch Available
Event History
Dec 15, 2019
CVE Published
via MITRE·09:16 PM
Data Sourced
via MITRE·09:16 PM
DescriptionWeakness
May 17, 2022
Advisory Published
07:57 PM
Frequently Asked Questions
1
What is the severity of CVE-2014-3652?
CVE-2014-3652 has a medium severity rating due to its potential for open redirect attacks.
2
How do I fix CVE-2014-3652?
To fix CVE-2014-3652, ensure that you upgrade to a version of Keycloak that addresses the open redirect vulnerability.
3
Which versions of Keycloak are affected by CVE-2014-3652?
CVE-2014-3652 affects Keycloak versions up to 1.1.0.Beta1 and specifically version 1.0.1 of Red Hat Keycloak.
4
What type of vulnerability is CVE-2014-3652?
CVE-2014-3652 is classified as an open redirect vulnerability involving improper validation of redirect URLs.
5
Who is impacted by CVE-2014-3652?
Users of JBoss Keycloak versions that are affected may be impacted by CVE-2014-3652 if they do not implement proper URL validation.