A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.
CVE ID: CVE-2024-8883
Vendor: Red Hat
Product: Red Hat Build of Keycloak
http/cves/2024/CVE-2024-8883.yaml
EPSS Score: 0.24% (probability of being exploited)
EPSS Percentile: 64.04% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)