CVE-2024-2419

CVSS v3.1 7.1 (High)
71% Progress
EPSS 0.04 % (16th)
0.04% Progress
Advisories 1
NVD Status Awaiting Analysis

A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to the theft of an access token, making it possible for the attacker to impersonate other users. It is very similar to CVE-2023-6291.

Weaknesses
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Related CVEs
CVE Status
PUBLISHED
NVD Status
Awaiting Analysis
CNA
Red Hat, Inc.
Published Date
2024-04-17 14:15:08
(5 months ago)
Updated Date
2024-04-17 16:15:08
(5 months ago)
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...