CVE-2024-8883
בינונית 6.1
תיאור (מקור, אנגלית)
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
מדדים
- CVSS 3.1
-
6.1 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 2% (אחוזון 100) נכון ל-6/8/2026
- CWE
- CWE-601
מוצרים מושפעים
redhat: build of keycloak; redhat: openshift container platform; redhat: openshift container platform for ibm z; redhat: openshift container platform for linuxone; redhat: openshift container platform for power; redhat: single sign-on
קישורים
- https://access.redhat.com/errata/RHSA-2024:6878 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6879 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6880 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6882 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6886 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6887 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6888 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6889 Vendor Advisory
- https://access.redhat.com/errata/RHSA-2024:6890 Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2024-8883 Vendor Advisory