Skip to content

OIDC Logout redirects can happen even if no id_token_hint is provided

Low
abstractj published GHSA-rvjg-gxwx-j5gf Apr 25, 2022

Package

maven org.keycloak.protocol.oidc (Maven)

Affected versions

< 18.0.0

Patched versions

18.0.0

Description

A flaw was found in keycloak. The OIDC logout endpoint does not have CSRF protection. The highest threat from this vulnerability is to system availability.

Severity

Low

CVE ID

CVE-2020-10734

Weaknesses

URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. Learn more on MITRE.

Credits