CVE-2024-1132

CVSS V2 None CVSS V3 None
Description
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.
Overview
  • CVE ID
  • CVE-2024-1132
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-04-17T13:21:19.130Z
  • Last Modified Date
  • 2024-06-20T05:13:10.891Z
References
Reference URL Reference Tags
https://access.redhat.com/errata/RHSA-2024:1860 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1861 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1862 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1864 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1866 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1867 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:1868 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:2945 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:3752 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:3762 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:3919 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/errata/RHSA-2024:3989 vendor-advisory x_refsource_REDHAT
https://access.redhat.com/security/cve/CVE-2024-1132 vdb-entry x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=2262117 issue-tracking x_refsource_REDHAT
History
Created Old Value New Value Data Type Notes
2024-06-26 06:07:25 Added to TrackCVE