{
  "threat_severity" : "Important",
  "public_date" : "2024-04-16T00:00:00Z",
  "bugzilla" : {
    "description" : "keycloak: path transversal in redirection validation",
    "id" : "2262117",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2262117"
  },
  "cvss3" : {
    "cvss3_base_score" : "8.1",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-22",
  "details" : [ "A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.", "A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL." ],
  "statement" : "Red Hat Build of Quarkus is not impacted as this CVE affects the server-side Keycloak execution, but Quarkus only acts as a Keycloak client in its quarkus-keycloak-authorization extension. For this reason, Quarkus is marked as having a Low impact.",
  "acknowledgement" : "Red Hat would like to thank Axel Flamcourt for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Migration Toolkit for Runtimes 1 on RHEL 8",
    "release_date" : "2024-06-13T00:00:00Z",
    "advisory" : "RHSA-2024:3919",
    "cpe" : "cpe:/a:redhat:migration_toolkit_runtimes:1.0::el8",
    "package" : "mtr/mtr-operator-bundle:1.2-23"
  }, {
    "product_name" : "Migration Toolkit for Runtimes 1 on RHEL 8",
    "release_date" : "2024-06-13T00:00:00Z",
    "advisory" : "RHSA-2024:3919",
    "cpe" : "cpe:/a:redhat:migration_toolkit_runtimes:1.0::el8",
    "package" : "mtr/mtr-rhel8-operator:1.2-15"
  }, {
    "product_name" : "Migration Toolkit for Runtimes 1 on RHEL 8",
    "release_date" : "2024-06-13T00:00:00Z",
    "advisory" : "RHSA-2024:3919",
    "cpe" : "cpe:/a:redhat:migration_toolkit_runtimes:1.0::el8",
    "package" : "mtr/mtr-web-container-rhel8:1.2-16"
  }, {
    "product_name" : "Migration Toolkit for Runtimes 1 on RHEL 8",
    "release_date" : "2024-06-13T00:00:00Z",
    "advisory" : "RHSA-2024:3919",
    "cpe" : "cpe:/a:redhat:migration_toolkit_runtimes:1.0::el8",
    "package" : "mtr/mtr-web-executor-container-rhel8:1.2-14"
  }, {
    "product_name" : "MTA-6.2-RHEL-9",
    "release_date" : "2024-06-20T00:00:00Z",
    "advisory" : "RHSA-2024:3989",
    "cpe" : "cpe:/a:redhat:migration_toolkit_applications:6.2::el9",
    "package" : "mta/mta-windup-addon-rhel9:6.2.3-2"
  }, {
    "product_name" : "Red Hat AMQ Broker 7",
    "release_date" : "2024-06-10T00:00:00Z",
    "advisory" : "RHSA-2024:3752",
    "cpe" : "cpe:/a:redhat:amq_broker:7.10"
  }, {
    "product_name" : "Red Hat AMQ Broker 7",
    "release_date" : "2024-06-10T00:00:00Z",
    "advisory" : "RHSA-2024:3762",
    "cpe" : "cpe:/a:redhat:amq_broker:7.11",
    "package" : "keycloak"
  }, {
    "product_name" : "Red Hat AMQ Broker 7",
    "release_date" : "2024-05-21T00:00:00Z",
    "advisory" : "RHSA-2024:2945",
    "cpe" : "cpe:/a:redhat:amq_broker:7.12"
  }, {
    "product_name" : "Red Hat build of Keycloak 22",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1867",
    "cpe" : "cpe:/a:redhat:build_keycloak:22::el9",
    "package" : "rhbk/keycloak-operator-bundle:22.0.10-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 22",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1867",
    "cpe" : "cpe:/a:redhat:build_keycloak:22::el9",
    "package" : "rhbk/keycloak-rhel9:22-13"
  }, {
    "product_name" : "Red Hat build of Keycloak 22",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1867",
    "cpe" : "cpe:/a:redhat:build_keycloak:22::el9",
    "package" : "rhbk/keycloak-rhel9-operator:22-16"
  }, {
    "product_name" : "Red Hat build of Keycloak 22.0.10",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1868",
    "cpe" : "cpe:/a:redhat:build_keycloak:22",
    "package" : "keycloak"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.6 for RHEL 7",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1860",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7.6::el7",
    "package" : "rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el7sso"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.6 for RHEL 8",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1861",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7.6::el8",
    "package" : "rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el8sso"
  }, {
    "product_name" : "Red Hat Single Sign-On 7.6 for RHEL 9",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1862",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7.6::el9",
    "package" : "rh-sso7-keycloak-0:18.0.13-1.redhat_00001.1.el9sso"
  }, {
    "product_name" : "RHEL-8 based Middleware Containers",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1864",
    "cpe" : "cpe:/a:redhat:rhosemc:1.0::el8",
    "package" : "rh-sso-7/sso76-openshift-rhel8:7.6-46"
  }, {
    "product_name" : "RHSSO 7.6.8",
    "release_date" : "2024-04-16T00:00:00Z",
    "advisory" : "RHSA-2024:1866",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7.6",
    "package" : "rh-sso7-keycloak"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat build of Apicurio Registry 2",
    "fix_state" : "Affected",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:service_registry:2"
  }, {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Not affected",
    "package_name" : "org.keycloak/keycloak-core",
    "cpe" : "cpe:/a:redhat:quarkus:2",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat build of Quarkus",
    "fix_state" : "Not affected",
    "package_name" : "org.keycloak/keycloak-core",
    "cpe" : "cpe:/a:redhat:quarkus:3"
  }, {
    "product_name" : "Red Hat Data Grid 8",
    "fix_state" : "Not affected",
    "package_name" : "org.wildfly.security-wildfly-elytron-parent",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:8"
  }, {
    "product_name" : "Red Hat Decision Manager 7",
    "fix_state" : "Out of support scope",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_brms_platform:7"
  }, {
    "product_name" : "Red Hat Fuse 7",
    "fix_state" : "Fix deferred",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "impact" : "low"
  }, {
    "product_name" : "Red Hat JBoss Data Grid 7",
    "fix_state" : "Not affected",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:jboss_data_grid:7"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 6",
    "fix_state" : "Out of support scope",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:6"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 7",
    "fix_state" : "Not affected",
    "package_name" : "keycloak-core",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:7"
  }, {
    "product_name" : "Red Hat Process Automation 7",
    "fix_state" : "Affected",
    "package_name" : "keycloak",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_bpms_platform:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-1132\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-1132" ],
  "name" : "CVE-2024-1132",
  "mitigation" : {
    "value" : "No current mitigation is available for this vulnerability.",
    "lang" : "en:us"
  },
  "csaw" : false
}