VulnerabilityModified
CVE-2018-14658
A flaw was found in JBOSS Keycloak 3.2.1.Final.
MEDIUM 6.1EPSS 1.10%
Does this matter?
Lower severity and a low EPSS score (1.10%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 1.10% probability · 64th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- redhat/keycloak
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:3592Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3593Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3595Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3592Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3593Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3595Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.