CVE-2024-8883 | Keycloak: vulnerable redirect uri validation results in open redirec

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes to be exposed to the attacker, potentially leading to session hijacking.

Published: 2024-09-19 Last update: 2024-11-26 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2024-8883 is rated Moderate Risk (57.8/100): CVSS Medium severity, with high exploitation likelihood (EPSS 6.59%, 91th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.49% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2024-8883

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-27 5.11% 6.59% +1.49%
2 2026-03-19 4.97% 5.11% +0.13%
3 2026-03-04 4.97%

Full EPSS history (45 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2024-8883

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.1 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 2.7 [email protected]
6.1 3.1 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:R)
A real person has to do something—click, install, enable—otherwise it doesn’t land.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:L)
Some sensitive info could get out, but not a total data dump.
Integrity (I:L)
Attackers could change some data, but it’s limited—not everything goes.
Availability (A:N)
Service keeps running; no real outage angle.
2.8 2.7 [email protected]

Weakness enumeration for CVE-2024-8883

GitHub Security Advisory for CVE-2024-8883

GHSA-w8gr-xwp4-r9f7 · Severity: medium · Ecosystem: maven — Keycloak has Vulnerable Redirect URI Validation Results in Open Redirect

OS Trackers for CVE-2024-8883

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2024-8883

Affected software / configurations for CVE-2024-8883

Vendor Product Version Raw CPE
redhat build_of_keycloak cpe:2.3:a:redhat:build_of_keycloak:-:*:*:*:text-only:*:*:*
redhat openshift_container_platform 4.11 cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
redhat openshift_container_platform 4.12 cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
redhat openshift_container_platform_for_ibm_z 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.9:*:*:*:*:*:*:*
redhat openshift_container_platform_for_ibm_z 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_ibm_z:4.10:*:*:*:*:*:*:*
redhat openshift_container_platform_for_linuxone 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:*
redhat openshift_container_platform_for_linuxone 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*
redhat openshift_container_platform_for_power 4.9 cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
redhat openshift_container_platform_for_power 4.10 cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
redhat single_sign-on cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
redhat single_sign-on 7.6 cpe:2.3:a:redhat:single_sign-on:7.6:*:*:*:*:*:*:*

References for CVE-2024-8883

URL Tags
https://access.redhat.com/errata/RHSA-2024:10385
https://access.redhat.com/errata/RHSA-2024:10386
https://access.redhat.com/errata/RHSA-2024:6878 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6879 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6880 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6882 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6886 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6887 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6888 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6889 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:6890 Vendor Advisory
https://access.redhat.com/errata/RHSA-2024:8823
https://access.redhat.com/errata/RHSA-2024:8824
https://access.redhat.com/errata/RHSA-2024:8826
https://access.redhat.com/security/cve/CVE-2024-8883 Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2312511 Issue Tracking Vendor Advisory
https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/protocol/oidc/utils/RedirectUtils.java Product
cvelogic Threat Intelligence