PT-2024-20311 · Red Hat · Keycloak

·

CVE-2024-2419

·

Published

2024-04-17

·

Updated

2024-04-17

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak's redirect uri validation logic, which may allow a bypass of otherwise explicitly allowed hosts. This issue could lead to the theft of an access token, enabling an attacker to impersonate other users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-2419
GHSA-MRV8-PQFJ-7GP5

Affected Products

Keycloak