First published: Wed Jun 01 2022(Updated: )
An open redirection vulnerability (open redirect) exists in keycloak auth endpoint. URL can be mentioned as the value of redirect_uri query parameter and it successfully redirects to it. References: <a href="https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0">https://github.com/syedsohaibkarim/OpenRedirect-Keycloak18.0.0</a>
Affected Software | Affected Version | How to fix |
---|---|---|
Red Hat Build of Keycloak |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2092434 is high due to the potential for exploitation via open redirection.
To mitigate REDHAT-BUG-2092434, ensure that your Keycloak configuration properly validates the redirect_uri parameter.
REDHAT-BUG-2092434 affects Red Hat Build of Keycloak.
REDHAT-BUG-2092434 is classified as an open redirection vulnerability.
Yes, exploitation of REDHAT-BUG-2092434 can lead users to malicious sites, increasing the risk of phishing or other attacks.