REDHAT-BUG-2445988: High severity Red Hat Keycloak vulnerability
A flaw was found in Keycloak's redirecturi validation logic. This issue may allow bypassing the allwed path in a redirect URIs that use a wilcard. A successful attack may lead to the theft of an access token if the attacker controls another path on the same web server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2445988?
The severity of REDHAT-BUG-2445988 is considered high due to the potential for access token theft.
How do I fix REDHAT-BUG-2445988?
To fix REDHAT-BUG-2445988, ensure that the redirect_uri validation logic is properly configured to disallow wildcard paths.
What is the impact of REDHAT-BUG-2445988?
The impact of REDHAT-BUG-2445988 includes the risk of unauthorized access to secured resources through token theft.
Which versions of Keycloak are affected by REDHAT-BUG-2445988?
REDHAT-BUG-2445988 affects Red Hat Keycloak versions that utilize wildcard characters in redirect URIs.
Can an attacker exploit REDHAT-BUG-2445988 remotely?
Yes, an attacker can exploit REDHAT-BUG-2445988 remotely if they control another path on the same web server.