REDHAT-BUG-1770276: Low severity keycloak vulnerability
The logout endpoint /oauth/logout?redirect=url can be abused to redirect logged in users to arbitrary web pages. This vulnerability could be used in phishing attacks.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-11318
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1770276?
The severity of REDHAT-BUG-1770276 is classified as a medium risk due to its potential to facilitate phishing attacks.
How do I fix REDHAT-BUG-1770276?
To fix REDHAT-BUG-1770276, implement validation on the redirect URL in the logout endpoint to ensure it only redirects to trusted domains.
Who is affected by REDHAT-BUG-1770276?
Red Hat Keycloak users are affected by REDHAT-BUG-1770276, specifically those using the logout functionality.
What type of attack can REDHAT-BUG-1770276 facilitate?
REDHAT-BUG-1770276 can facilitate phishing attacks by redirecting users to malicious websites.
When was REDHAT-BUG-1770276 reported?
REDHAT-BUG-1770276 was reported as a vulnerability in the Red Hat Bugzilla system.