"value":"A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"URL Redirection to Untrusted Site ('Open Redirect')",
"cweId":"CWE-601"
}
]
}
]
},
"affects":{
"vendor":{
"vendor_data":[
{
"vendor_name":"Red Hat",
"product":{
"product_data":[
{
"product_name":"Red Hat Build of Keycloak",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
}
]
}
},
{
"product_name":"Red Hat build of Keycloak 22",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"22.0.13-1",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"22-18",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"22-21",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat build of Keycloak 24",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24.0.8-1",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24-17",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
},
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"24-17",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat Single Sign-On 7",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"defaultStatus":"unaffected"
}
}
]
}
},
{
"product_name":"Red Hat Single Sign-On 7.6 for RHEL 7",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"0:18.0.18-1.redhat_00001.1.el7sso",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat Single Sign-On 7.6 for RHEL 8",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"0:18.0.18-1.redhat_00001.1.el8sso",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat Single Sign-On 7.6 for RHEL 9",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"0:18.0.18-1.redhat_00001.1.el9sso",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"RHEL-8 based Middleware Containers",
"version":{
"version_data":[
{
"version_value":"not down converted",
"x_cve_json_5_version_data":{
"versions":[
{
"version":"7.6-54",
"lessThan":"*",
"versionType":"rpm",
"status":"unaffected"
}
],
"defaultStatus":"affected"
}
}
]
}
},
{
"product_name":"Red Hat JBoss Enterprise Application Platform 8",