Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cjm2-j6cm-6p6m

Опубликовано: 02 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 26.5.7

26.5.7

EPSS

Процентиль: 36%
0.0044
Низкий

7.3 High

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 7.3
redhat
4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
nvd
4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
debian
4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who contr ...

EPSS

Процентиль: 36%
0.0044
Низкий

7.3 High

CVSS3

Дефекты

CWE-601