Description
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1770276
https://issues.redhat.com/browse/KEYCLOAK-11318
Related Vulnerabilities
CVE-2023-36477 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ckeditor-ui
CVE-2022-43183 Vulnerability in maven package com.xuxueli:xxl-job
CVE-2023-42276 Vulnerability in maven package cn.hutool:hutool-json
CVE-2022-4245 Vulnerability in maven package org.codehaus.plexus:plexus-utils
CVE-2020-2275 Vulnerability in maven package org.jenkins-ci.plugins:copy-data-to-workspace-plugin