REDHAT-BUG-2312511: Medium severity Red Hat Keycloak vulnerability
It is possible to configure Keycloak in such a manner that any application with a 'Valid Redirect URI' set to http://localhost or http://127.0.0.1 can be redirected to an arbitrary URL of the attackers choosing. In the process sensitive information such as the authorization code can be exposed to the attacker, resulting in possible session hijacking.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Configure Keycloak client redirect URIs so that 'Valid Redirect URI' does not include http://localhost or http://127.0.0.1, to prevent redirecting to attacker-chosen arbitrary URLs (and potential session hijacking via exposed authorization codes).
Keycloak Valid Redirect URI (client redirect URIs) = Do not allow http://localhost and http://127.0.0.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2312511?
The severity of REDHAT-BUG-2312511 is considered high due to its potential for arbitrary URL redirection.
How do I fix REDHAT-BUG-2312511?
To fix REDHAT-BUG-2312511, ensure that the 'Valid Redirect URI' settings do not include localhost or 127.0.0.1 in any applications.
What applications are affected by REDHAT-BUG-2312511?
REDHAT-BUG-2312511 affects configurations in Red Hat Build of Keycloak.
What kind of attack is possible due to REDHAT-BUG-2312511?
REDHAT-BUG-2312511 allows attackers to redirect users to arbitrary URLs, potentially leading to phishing attacks.
Is there a CVE associated with REDHAT-BUG-2312511?
Currently, there is no specific CVE associated with REDHAT-BUG-2312511.