---
id: CVE-2024-1132
title: >-
  A flaw was found in Keycloak, where it does not properly validate URLs
  included in a redirect
summary: >-
  A flaw was found in Keycloak, where it does not properly validate URLs
  included in a redirect. This issue could allow an attacker to construct a
  malicious request to bypass validation and access other URLs and sensitive
  information withi…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'
cwe:
  - CWE-22
  - CWE-22
vendor: redhat
product: build_of_keycloak
affected:
  - build_of_keycloak
  - jboss_middleware_text-only_advisories = 1.0
  - 'keycloak >= 21.1.0, < 22.0.10'
  - 'keycloak >= 23.0.0, < 24.0.3'
  - migration_toolkit_for_applications = 1.0
  - migration_toolkit_for_runtimes
  - openshift_container_platform = 4.11
  - openshift_container_platform = 4.12
  - openshift_container_platform_for_ibm_z = 4.9
  - openshift_container_platform_for_ibm_z = 4.10
  - openshift_container_platform_for_linuxone = 4.9
  - openshift_container_platform_for_linuxone = 4.10
  - openshift_container_platform_for_power = 4.9
  - openshift_container_platform_for_power = 4.10
  - single_sign-on
  - single_sign-on = 7.6
patched:
  - keycloak 24.0.3
published: '2024-04-17'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1132'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:1860'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1861'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1862'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1864'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1866'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3752'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3762'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3919'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:3989'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1132'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2262117'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1860'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1861'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1862'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1864'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1866'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3752'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3762'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3919'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:3989'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1132'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2262117'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01552
epssPercentile: 0.73582
ingestedAt: '2026-08-04T08:38:40.789Z'
---

## Overview

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

## Affected

- `build_of_keycloak`
- `jboss_middleware_text-only_advisories = 1.0`
- `keycloak >= 21.1.0, < 22.0.10`
- `keycloak >= 23.0.0, < 24.0.3`
- `migration_toolkit_for_applications = 1.0`
- `migration_toolkit_for_runtimes`
- `openshift_container_platform = 4.11`
- `openshift_container_platform = 4.12`
- `openshift_container_platform_for_ibm_z = 4.9`
- `openshift_container_platform_for_ibm_z = 4.10`
- `openshift_container_platform_for_linuxone = 4.9`
- `openshift_container_platform_for_linuxone = 4.10`
- `openshift_container_platform_for_power = 4.9`
- `openshift_container_platform_for_power = 4.10`
- `single_sign-on`
- `single_sign-on = 7.6`

## Remediation

Upgrade past the affected range:

- `keycloak 24.0.3`
