keycloak: Open Redirect in Login and Logout
Published Nov 13, 2018
6.1
MEDIUMCVSS 3.0
EPSS 1.10%
Description
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
Affected products
-
- Version 3.2.1.FinalStatusaffectedConstraints-
- Version
No data.
Red Hat Single Sign-On 7.2 for RHEL 6
rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el6
Fixed · RHSA-2018:3592
Red Hat Single Sign-On 7.2 for RHEL 7
rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el7
Fixed · RHSA-2018:3593
Red Hat Single Sign-On 7.2.5 zip
n/a
Fixed · RHSA-2018:3595
Red Hat Fuse 7
keycloak
Will not fix
Red Hat Mobile Application Platform 4
keycloak
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Single Sign-On 7.2 for RHEL 6 | rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el6 | Fixed | RHSA-2018:3592 |
| Red Hat Single Sign-On 7.2 for RHEL 7 | rh-sso7-keycloak-0:3.4.14-1.Final_redhat_00001.1.jbcs.el7 | Fixed | RHSA-2018:3593 |
| Red Hat Single Sign-On 7.2.5 zip | n/a | Fixed | RHSA-2018:3595 |
| Red Hat Fuse 7 | keycloak | Will not fix | n/a |
| Red Hat Mobile Application Platform 4 | keycloak | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
AV:N/AC:M/Au:N/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 2, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 2, 2026 | 1.10% (0.01097) | 64.41th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.10% (0.01097) | 64.13th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.11% (0.00115) | 45.70th | v3 (v2023.03.01) |
| Nov 7, 2023 | 0.11% (0.00115) | 45.14th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.09% (0.00093) | 38.71th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00127) | 45.69th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.02% (0.01018) | 40.69th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.02% (0.01018) | 19.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.04% (0.01040) | 28.32th | v5 (v2026.06.15) |
| Apr 14, 2021 | 1.04% (0.01040) | 0.00th | v1 |
References (9)
- https://access.redhat.com/errata/RHSA-2018:3592 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3593 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3595 vendor-advisoryx_refsource_REDHATVendor Advisory
- https://access.redhat.com/security/cve/CVE-2018-14658 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1625409 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-3qh2-mccc-q5m6 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-14658
- https://www.cve.org/CVERecord?id=CVE-2018-14658
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2018:3592 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3593 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/errata/RHSA-2018:3595 | vendor-advisoryx_refsource_REDHATVendor Advisory | |
| https://access.redhat.com/security/cve/CVE-2018-14658 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1625409 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14658 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-3qh2-mccc-q5m6 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-14658 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-14658 |
Change history (0)
No recorded changes yet.