VDB
Sign up
HIGH7.3

GHSA-cjm2-j6cm-6p6m

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

Quick fix

GHSA-cjm2-j6cm-6p6m — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

Details

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 26.5.7
Fix# pom.xml: bump <version>26.5.7</version> for org.keycloak:keycloak-services

References