CVE-2024-42759
Lun, 09/09/2024 – 19:15
CVE-2024-42759
CVE-2024-42759
Lun, 09/09/2024 – 19:15
CVE-2024-42759
CVE-2024-24510
Lun, 09/09/2024 – 19:15
CVE-2024-24510
CVE-2024-7341
Lun, 09/09/2024 – 19:15
CVE-2024-7341
CVE-2024-7318
Lun, 09/09/2024 – 19:15
CVE-2024-7318
CVE-2024-7260
Lun, 09/09/2024 – 19:15
CVE-2024-7260
Once a crafted URL is made, it can be sent to a Keycloak admin via email for example. This will trigger this vulnerability when the user visits the page and clicks the link. A malicious actor can use this to target users they know are Keycloak admins for further attacks. It may also be possible to bypass other domain-related security checks, such as supplying this as a OAuth redirect uri. The malicious actor can further obfuscate the redirect_uri using URL encoding, to hide the text of the actual malicious website domain.
CVE-2024-44720
Lun, 09/09/2024 – 16:15
CVE-2024-44720
CVE-2024-8605
Lun, 09/09/2024 – 16:15
CVE-2024-8605
CVE-2024-8604
Lun, 09/09/2024 – 16:15
CVE-2024-8604
CVE-2024-7015
Lun, 09/09/2024 – 14:15
CVE-2024-7015
CVE-2024-44375
Lun, 09/09/2024 – 14:15
CVE-2024-44375