icon

We found results for “

CVE-2024-8883

Good to know:

icon
icon

Date: September 19, 2024

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

Language: Java

Severity Score

Severity Score

Weakness Type (CWE)

URL Redirection to Untrusted Site ('Open Redirect')

CWE-601

Top Fix

icon

Upgrade Version

Upgrade to version org.keycloak:keycloak-server-spi-private:25.0.0;org.keycloak:keycloak-server-spi-private:23.0.0;org.keycloak:keycloak-server-spi-private:15.1.0;org.keycloak:keycloak-server-spi-private:24.0.5;org.keycloak:keycloak-server-spi-private:19.0.0;org.keycloak:keycloak-server-spi-private:18.0.1;org.keycloak:keycloak-server-spi-private:24.0.4;org.keycloak:keycloak-server-spi-private:10.0.0;org.keycloak:keycloak-services:1.5.0-Final;org.keycloak:keycloak-services:25.0.6;org.keycloak:keycloak-services:25.0.6;org.keycloak:keycloak-services:25.0.6;org.jboss.aerogear.unifiedpush:unifiedpush-auth-server:1.0.2

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

Do you need more information?

Contact Us