Skip to content

Path traversal in the redirect validation

High
abstractj published GHSA-mrv8-pqfj-7gp5 Apr 17, 2024

Package

maven org.keycloak.protocol.oidc.utils (Maven)

Affected versions

< 22.0.10, < 24.0.3

Patched versions

22.0.10, 24.0.3

Description

An issue was found in the redirect_uri validation logic that allows for a bypass of otherwise explicitly allowed hosts.

Severity

High

CVE ID

CVE-2024-2419