CVE-2024-8883

Aliases:GHSA-w8gr-xwp4-r9f7
Modified
Published: 19 Sept 2024, 15:48
Last modified:01 Apr 2026, 13:27

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
1.96% LOW
2% probability -1.43%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Sept 2024, 15:48
Published
Vulnerability first disclosed
01 Apr 2026, 13:27
Last Modified
Vulnerability information updated

Description

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 1.96% Percentile: 78%

Techniques & Countermeasures

  • CWE-601URL Redirection to Untrusted Site ('Open Redirect')

    The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Affected Systems

  • org.keycloakkeycloak-services

    < 22.0.13 | ≥ 23.0.0, < 24.0.8 | ≥ 25.0.0, < 25.0.6

  • redhatbuild_of_keycloak

    na

  • redhatopenshift_container_platform

    4.11 | 4.12

  • redhatopenshift_container_platform_for_ibm_z

    4.9 | 4.10

  • redhatopenshift_container_platform_for_linuxone

    4.9 | 4.10

  • redhatopenshift_container_platform_for_power

    4.9 | 4.10

  • redhatsingle_sign-on

    na | 7.6

References (21)