Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-72vp-xfrc-42xm

Опубликовано: 17 апр. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 8.1

Описание

Keycloak path traversal vulnerability in redirection validation

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.

Acknowledgements:

Special thanks to Axel Flamcourt for reporting this issue and helping us improve our project.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 22.0.10

22.0.10

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 23.0.0, < 24.0.3

24.0.3

EPSS

Процентиль: 44%
0.00213
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
redhat
почти 2 года назад

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

CVSS3: 8.1
nvd
почти 2 года назад

A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field, and requires user interaction within the malicious URL.

CVSS3: 8.1
debian
почти 2 года назад

A flaw was found in Keycloak, where it does not properly validate URLs ...

EPSS

Процентиль: 44%
0.00213
Низкий

8.6 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-22