Description
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1770276
https://issues.redhat.com/browse/KEYCLOAK-11318
Related Vulnerabilities
CVE-2023-28672 Vulnerability in maven package org.jenkinsci.plugins:octoperf
CVE-2023-25157 Vulnerability in maven package org.geoserver.community:gs-jdbcconfig
CVE-2023-47112 Vulnerability in maven package org.rundeck:rundeck
CVE-2023-36478 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2022-44262 Vulnerability in maven package org.ff4j:ff4j-core