Lucene search

K
osvGoogleOSV:CVE-2018-14658
HistoryNov 13, 2018 - 7:29 p.m.

CVE-2018-14658

2018-11-1319:29:00
Google
osv.dev
13

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

46.6%

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

46.6%