CVE-2024-1132: Keycloak: path transversal in redirection validation
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
Acknowledgements: Special thanks to Axel Flamcourt for reporting this issue and helping us improve our project.
Other sources
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
Version affected: Keycloak >= 21.1.0. Red Hat Build of Keycloak affected since beginning. Red Hat Single Sign-On affected since 7.6.5
— Red Hat
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 24.0.3 - Upgrade
Upgrade
maven/org.keycloak:keycloak-servicesto a version that resolves this vulnerability.Fixed in 22.0.10 - Upgrade
Upgrade
redhat/keycloakto a version that resolves this vulnerability.Fixed in 22.0.10 - Upgrade
Upgrade
redhat/keycloakto a version that resolves this vulnerability.Fixed in 24.0.3 - Upgrade
Upgrade
redhat/rhbkto a version that resolves this vulnerability.Fixed in 22.0.10 - Upgrade
Upgrade
redhat/rhssoto a version that resolves this vulnerability.Fixed in 7.6.8
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1132?
CVE-2024-1132 has a medium severity rating due to its potential for unauthorized URL access and data exposure.
How do I fix CVE-2024-1132?
To resolve CVE-2024-1132, upgrade to Keycloak version 24.0.3 or 22.0.10 depending on your installation.
What types of systems are affected by CVE-2024-1132?
CVE-2024-1132 affects Keycloak versions 23.0.0 to 24.0.3 and versions prior to 22.0.10.
What could an attacker achieve by exploiting CVE-2024-1132?
An attacker exploiting CVE-2024-1132 can bypass URL validation, potentially accessing sensitive information or launching further attacks.
Is there a patch available for CVE-2024-1132?
Yes, a patch is available in Keycloak versions 24.0.3 and 22.0.10.