Description
A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout process. The redirect_uri parameter associated with the openid-connect logout protocol does not properly validate the provided URL.
Problem types
URL Redirection to Untrusted Site ('Open Redirect')
Product status
Timeline
| 2025-11-06: | Reported to Red Hat. |
| 2025-11-06: | Made public. |
Credits
Red Hat would like to thank Edcarlos Junior for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-12789
bugzilla.redhat.com/show_bug.cgi?id=2413001 (RHBZ#2413001)