CVE-2024-8883

Aliases:GHSA-w8gr-xwp4-r9f7RHSA-2024:10386CGA-98hf-jqr8-rcv6CGA-xgg7-2jcc-rhvq
Modified
Published: 19 Sept 2024, 15:48
Last modified:04 Aug 2026, 11:08

Vulnerability Summary

Overall Risk (default)
medium
25/100
CVSS Score
6.1 MEDIUM
v3.1 (cve.org)
EPSS Score
2.11% LOW
2% probability -1.28%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

19 Sept 2024, 15:48
Published
Vulnerability first disclosed
04 Aug 2026, 11:08
Last Modified
Vulnerability information updated

Description

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS Trends

Current EPSS score: 2.11% Percentile: 81%

Techniques & Countermeasures

  • CWE-601URL Redirection to Untrusted Site ('Open Redirect')

    The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Affected Systems

  • chainguardkeycloak

    < 25.0.6-r0

  • wolfikeycloak

    < 25.0.6-r0

  • org.keycloakkeycloak-services

    < 22.0.13 | ≥ 23.0.0, < 24.0.8 | ≥ 25.0.0, < 25.0.6

  • redhatbuild_of_keycloak

    na

  • redhatopenshift_container_platform

    4.11 | 4.12

  • redhatopenshift_container_platform_for_ibm_z

    4.9 | 4.10

  • redhatopenshift_container_platform_for_linuxone

    4.9 | 4.10

  • redhatopenshift_container_platform_for_power

    4.9 | 4.10

  • redhatsingle_sign-on

    na | 7.6

  • redhateap8-eap-product-conf-parent

    < 0:800.4.1-1.GA_redhat_00001.1.el8eap | < 0:800.4.1-1.GA_redhat_00001.1.el9eap

  • redhateap8-eap-product-conf-wildfly-ee-feature-pack

    < 0:800.4.1-1.GA_redhat_00001.1.el8eap | < 0:800.4.1-1.GA_redhat_00001.1.el9eap

  • redhateap8-wildfly

    < 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap

  • redhateap8-wildfly-java-jdk11

    < 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap

  • redhateap8-wildfly-java-jdk17

    < 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap

  • redhateap8-wildfly-java-jdk21

    < 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap

  • redhateap8-wildfly-modules

    < 0:8.0.4-3.GA_redhat_00007.1.el8eap | < 0:8.0.4-3.GA_redhat_00007.1.el9eap

References (30)