The vendor explicitly identifies these products or versions as containing the fix.
- rhbk/keycloak-operator-bundle@sha256:2c25b3107aee4f1fc25530f099fa683ba3077c185d581e7caa777c4410383085_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:0d3ea94f75c1b4528722db2c216ff2267ec17ba16adf3f703afb82354f0fdc68_arm64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:330350e0cd77afca88886156c2668ae4bca75865e90362cbcf9657197bfa21e8_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:399c59b8e63de5b6aa4e64008644550b98feb0957214e58dc7c6a5246dde3c87_ppc64le as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9-operator@sha256:f9f35a75d3029edf5ff82351c0b60ad0dd8672c3fa8f22f672954c248f9e0c63_s390x as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:130dfc422476647b5098a317a38964e7ea6a2a3f1a63d91f91dfb993921b356b_ppc64le as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:8a6fd6c12811ce179fc1248c63a152d173c12866b84f8b8364f4f3ed42b7ba58_s390x as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:cc475d34ac199de0908a32efa630c219469076feb74fd970d617c40cc90911f8_arm64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-rhel9@sha256:fc0390f65497ad6274f3db55ac796eb792255a8780578ab4d98aec9f42c23bc0_amd64 as a component of Red Hat build of Keycloak 26.4
- rhbk/keycloak-operator-bundle@sha256:06ee2f18c4218c9a095360efa2023b2080aa81e04a08363dbcb1d14de85a5d0d_amd64 as a component of Red Hat build of Keycloak 26.6
- rhbk/keycloak-rhel9-operator@sha256:0024d9a0b69b61004a0d35ee25eefc443fe75ce2563b1645ec318caacc0aa23c_s390x as a component of Red Hat build of Keycloak 26.6
- rhbk/keycloak-rhel9-operator@sha256:2eeef9cec3ee8e3cfdb1c4b7377582b4a5378f852e11872eeb74597ad9ec0615_amd64 as a component of Red Hat build of Keycloak 26.6
- Summary
- A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Identifiers (URIs), a remote attacker can manipulate the authentication process by crafting a special web address. If a user clicks this link, the client application might incorrectly prioritize attacker-controlled information over legitimate data. This vulnerability, known as HTTP parameter pollution, could allow an attacker to bypass security measures or gain unauthorized access to resources.
- Remediation
- Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.
