Red Hat Build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
- < 1.0
A vulnerability exists in Keycloak's handling of redirect URIs that utilize wildcards. This flaw allows an attacker, who controls a different path on the same web server, to bypass the validation of allowed paths in redirect URIs. Exploiting this vulnerability could lead to the theft of an access token, resulting in unauthorized information disclosure.
By bypassing the redirect URI validation, an attacker could potentially steal access tokens, leading to unauthorized access to sensitive information.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.