Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.1 Maven

Keycloak Open Redirect

GHSA-3qh2-mccc-q5m6 · CVE-2018-14658

Published · Modified

Description

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack

Ready to move

Start Securing

Free, no credit card | First findings in minutes