TROYANOSYVIRUS
Volver a CVEs

CVE-2024-8883

MEDIUM
6.1

Descripcion

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

Detalles CVE

Puntuacion CVSS v3.16.1
SeveridadMEDIUM
Vector CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Vector de ataqueNETWORK
ComplejidadLOW
Privilegios requeridosNONE
Interaccion usuarioREQUIRED
Publicado9/19/2024
Ultima modificacion11/26/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

redhat:build_of_keycloakredhat:openshift_container_platformredhat:openshift_container_platform_for_ibm_zredhat:openshift_container_platform_for_linuxoneredhat:openshift_container_platform_for_powerredhat:single_sign-on

Debilidades (CWE)

CWE-601

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.