← Vulnerability feed

Vulnerability record · CVE-2024-1132 · published 17 April 2024

CVE-2024-1132: Redhat build of keycloak path traversal vulnerability

Redhat · Build Of Keycloak

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

8.1 CVSS 3.1 High EPSS 1.6% · top 25.9% CWE-22 · Path traversal
8.1CVSS 3.1 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
28References
4 Aug 2026Last modified by NVD

Description

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://access.redhat.com/errata/RHSA-2024:1860 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1861 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1862 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1864 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1866 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1867 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1868 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:2945 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3752 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3762 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3919 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3989 Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-1132 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2262117 Issue TrackingVendor Advisory
https://access.redhat.com/errata/RHSA-2024:1860 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1861 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1862 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1864 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1866 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1867 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:1868 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:2945 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3752 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3762 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3919 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:3989 Vendor Advisory
https://access.redhat.com/security/cve/CVE-2024-1132 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2262117 Issue TrackingVendor Advisory

Track CVE-2024-1132 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-4437Apache Shiro hardcoded remember-me cipher key enables code executionApache Shiro before 1.2.5 uses a default cipher key for the "remember me" feature when no key is configured, allowing attackers to forge or decrypt r…KEVEPSS 93%analysed7.5CVE-2023-44487HTTP/2 Rapid Reset stream cancellation denial of serviceThe HTTP/2 protocol permits a client to cancel many streams quickly, and the server's handling of those resets consumes disproportionate resources. T…KEVEPSS 100%analysed6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed9.8CVE-2026-16442Redhat build of keycloak origin validation error vulnerabilityA flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…EPSS 0.31%9.8CVE-2022-1245Redhat keycloak missing authorization vulnerabilityA privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid ac…EPSS 1.4%9.8CVE-2019-14910Redhat keycloak improper authentication vulnerabilityA vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDA…EPSS 1.1%9.6CVE-2021-20195Redhat keycloak improper input validation vulnerabilityA flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to …EPSS 1.2%9.1CVE-2026-16443Redhat build of keycloak improper verification of cryptographic signature vulnerabilityA flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red…EPSS 0.26%

Source: NIST National Vulnerability Database (record CVE-2024-1132), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.