CVE-2024-2419: Red Hat Build Of Keycloak 22
High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in Keycloak's redirect_uri validation logic. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to the theft of an access token, making it possible for the attacker to impersonate other users. It is very similar to CVE-2023-6291.
Affected products
- Red Hat Red Hat Build Of Keycloak 22: before 22.0.10-1 (fixed in 22.0.10-1); before 22-13 (fixed in 22-13); before 22-16 (fixed in 22-16)
Published 2024-04-17. Last modified 2026-06-17.