Description
A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected versions of Keycloak Gatekeeper (Louketo): 6.0.1, 7.0.0
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1770276
https://issues.redhat.com/browse/KEYCLOAK-11318
Related Vulnerabilities
CVE-2016-1000229 Vulnerability in maven package org.webjars.npm:swagger-ui
CVE-2019-20364 Vulnerability in maven package org.igniterealtime.openfire:xmppserver
CVE-2020-1950 Vulnerability in maven package org.apache.tika:tika-parsers
CVE-2020-28847 Vulnerability in npm package valine
CVE-2022-42124 Vulnerability in maven package com.liferay:com.liferay.layout.page.template.service