Lucene search

K
osvGoogleOSV:GHSA-3QH2-MCCC-Q5M6
HistoryMay 13, 2022 - 1:34 a.m.

Keycloak Open Redirect

2022-05-1301:34:29
Google
osv.dev
17
jboss keycloak
flaw
open redirection

EPSS

0.001

Percentile

46.6%

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack

EPSS

0.001

Percentile

46.6%