Impact
A flaw in Keycloak allows an attacker to craft a web address that duplicates HTTP response parameters when a client application accepts broad redirect URIs. The duplication can cause the client application to treat attacker‑controlled data as if it were legitimate, potentially bypassing authentication checks or gaining unauthorized access to protected resources. This issue stems from HTTP parameter pollution vulnerabilities, classified under CWE‑1288, and could result in unauthorized privilege escalation within the identity and access management flow.
Affected Systems
The vulnerability affects the Red Hat Build of Keycloak, though no specific version ranges are listed in the advisory. All deployments of this build that permit unrestricted redirect URIs are potentially impacted; clients should review the configuration and update to any fixed releases.
Risk and Exploitability
The CVSS score of 4.2 indicates a medium severity risk. EPSS data are not available, but the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring an attacker to entice a user to click a malicious link that triggers the illicit OIDC response. If successful, the attacker could hijack the authentication response and bypass intended security controls.
OpenCVE Enrichment