A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a Valid Redirect URI is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Build_of_keycloak | Redhat | - (including) | - (including) |
Openshift_container_platform | Redhat | 4.11 (including) | 4.11 (including) |
Openshift_container_platform | Redhat | 4.12 (including) | 4.12 (including) |
Openshift_container_platform_for_ibm_z | Redhat | 4.9 (including) | 4.9 (including) |
Openshift_container_platform_for_ibm_z | Redhat | 4.10 (including) | 4.10 (including) |
Openshift_container_platform_for_linuxone | Redhat | 4.9 (including) | 4.9 (including) |
Openshift_container_platform_for_linuxone | Redhat | 4.10 (including) | 4.10 (including) |
Openshift_container_platform_for_power | Redhat | 4.9 (including) | 4.9 (including) |
Openshift_container_platform_for_power | Redhat | 4.10 (including) | 4.10 (including) |
Single_sign-on | Redhat | - (including) | - (including) |
Single_sign-on | Redhat | 7.6 (including) | 7.6 (including) |
Red Hat Build of Keycloak | RedHat | org.keycloak/keycloak-services | * |
Red Hat Build of Keycloak | RedHat | org.keycloak/keycloak-services | * |
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-operator-bundle:22.0.13-1 | * |
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-rhel9:22-18 | * |
Red Hat build of Keycloak 22 | RedHat | rhbk/keycloak-rhel9-operator:22-21 | * |
Red Hat build of Keycloak 24 | RedHat | rhbk/keycloak-operator-bundle:24.0.8-1 | * |
Red Hat build of Keycloak 24 | RedHat | rhbk/keycloak-rhel9:24-17 | * |
Red Hat build of Keycloak 24 | RedHat | rhbk/keycloak-rhel9-operator:24-17 | * |
Red Hat JBoss Enterprise Application Platform 8 | RedHat | org.keycloak/keycloak-services | * |
Red Hat JBoss Enterprise Application Platform 8 | RedHat | org.keycloak/keycloak-services | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-eap-product-conf-parent-0:800.4.1-1.GA_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-wildfly-0:8.0.4-3.GA_redhat_00007.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-activemq-artemis-0:2.33.0-1.redhat_00015.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-activemq-artemis-native-1:2.0.0-2.redhat_00005.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-aesh-extensions-0:1.8.0-2.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-aesh-readline-0:2.2.0-2.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-commons-codec-0:1.16.1-2.redhat_00007.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-commons-collections-0:3.2.2-28.redhat_2.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-commons-io-0:2.15.1-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-commons-lang-0:3.14.0-2.redhat_00006.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-apache-cxf-0:4.0.5-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-artemis-native-1:2.0.0-2.redhat_00005.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-artemis-wildfly-integration-0:2.0.1-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-asyncutil-0:0.1.0-2.redhat_00010.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-aws-java-sdk-0:1.12.284-2.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-cryptacular-0:1.2.5-2.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-eap-product-conf-parent-0:800.4.0-1.GA_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-fastinfoset-0:2.1.0-4.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-hibernate-0:6.2.31-1.Final_redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-hibernate-validator-0:8.0.1-3.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-hppc-0:0.8.1-2.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-insights-java-client-0:1.1.3-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jakarta-servlet-jsp-jstl-api-0:3.0.1-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jboss-logging-0:3.5.3-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jctools-0:4.0.2-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-jgroups-0:5.3.10-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-log4j-0:2.22.1-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-narayana-0:6.0.3-1.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-nimbus-jose-jwt-0:9.37.3-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-objectweb-asm-0:9.6.0-1.redhat_00002.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-pem-keystore-0:2.3.0-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-resteasy-extensions-0:2.0.1-3.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-resteasy-spring-0:3.0.1-2.Final_redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-saaj-impl-0:3.0.4-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-shibboleth-java-support-0:8.0.0-6.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-slf4j-0:2.0.16-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-snakeyaml-0:2.2.0-1.redhat_00001.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 | RedHat | eap8-wildfly-0:8.0.4-2.GA_redhat_00005.1.el8eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-eap-product-conf-parent-0:800.4.1-1.GA_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-0:8.0.4-3.GA_redhat_00007.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-activemq-artemis-0:2.33.0-1.redhat_00015.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-activemq-artemis-native-1:2.0.0-2.redhat_00005.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-aesh-extensions-0:1.8.0-2.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-aesh-readline-0:2.2.0-2.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-codec-0:1.16.1-2.redhat_00007.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-collections-0:3.2.2-28.redhat_2.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-io-0:2.15.1-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-commons-lang-0:3.14.0-2.redhat_00006.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-apache-cxf-0:4.0.5-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-artemis-native-1:2.0.0-2.redhat_00005.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-artemis-wildfly-integration-0:2.0.1-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-asyncutil-0:0.1.0-2.redhat_00010.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-aws-java-sdk-0:1.12.284-2.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-cryptacular-0:1.2.5-2.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-eap-product-conf-parent-0:800.4.0-1.GA_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-fastinfoset-0:2.1.0-4.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-hibernate-0:6.2.31-1.Final_redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-hibernate-validator-0:8.0.1-3.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-hppc-0:0.8.1-2.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-insights-java-client-0:1.1.3-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jakarta-servlet-jsp-jstl-api-0:3.0.1-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jboss-cert-helper-0:1.1.3-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jboss-logging-0:3.5.3-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jctools-0:4.0.2-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-jgroups-0:5.3.10-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-log4j-0:2.22.1-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-narayana-0:6.0.3-1.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-nimbus-jose-jwt-0:9.37.3-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-objectweb-asm-0:9.6.0-1.redhat_00002.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-pem-keystore-0:2.3.0-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-resteasy-extensions-0:2.0.1-3.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-resteasy-spring-0:3.0.1-2.Final_redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-saaj-impl-0:3.0.4-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-shibboleth-java-support-0:8.0.0-6.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-slf4j-0:2.0.16-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-snakeyaml-0:2.2.0-1.redhat_00001.1.el9eap | * |
Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9 | RedHat | eap8-wildfly-0:8.0.4-2.GA_redhat_00005.1.el9eap | * |
Red Hat Single Sign-On 7 | RedHat | org.keycloak/keycloak-services | * |
Red Hat Single Sign-On 7.6 for RHEL 7 | RedHat | rh-sso7-keycloak-0:18.0.18-1.redhat_00001.1.el7sso | * |
Red Hat Single Sign-On 7.6 for RHEL 8 | RedHat | rh-sso7-keycloak-0:18.0.18-1.redhat_00001.1.el8sso | * |
Red Hat Single Sign-On 7.6 for RHEL 9 | RedHat | rh-sso7-keycloak-0:18.0.18-1.redhat_00001.1.el9sso | * |
RHEL-8 based Middleware Containers | RedHat | rh-sso-7/sso76-openshift-rhel8:7.6-54 | * |