Lucene search

K
redhatcveRedhat.comRH:CVE-2018-14658
HistoryOct 08, 2019 - 4:15 p.m.

CVE-2018-14658

2019-10-0816:15:29
redhat.com
access.redhat.com
16

EPSS

0.001

Percentile

46.6%

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack

EPSS

0.001

Percentile

46.6%