Medium severity6.1NVD Advisory· Published Nov 13, 2018· Updated Jun 17, 2026
CVE-2018-14658
CVE-2018-14658
Description
A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.RedirectUtils before the redirect url is verified. This can lead to an Open Redirection attack
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-coreMaven | <= 3.2.1.Final | — |
Affected products
3Patches
Vulnerability mechanics
References
6- access.redhat.com/errata/RHSA-2018:3592nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3593nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2018:3595nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-3qh2-mccc-q5m6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-14658ghsaADVISORY
News mentions
0No linked articles in our index yet.