Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-1727

Опубликовано: 20 мая 2020
Источник: redhat
CVSS3: 6.4
EPSS Низкий

Описание

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.

A flaw was found in Keycloak, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7keycloakAffected
Red Hat OpenShift Application RuntimeskeycloakAffected
Red Hat Single Sign-On 7rh-sso7-keycloakAffected
Red Hat Runtimes Spring Boot 2.2.6keycloakFixedRHSA-2020:225201.06.2020
Red Hat Single Sign-On 7.4.0FixedRHSA-2020:562517.12.2020
Text-Only RHOARFixedRHSA-2020:290523.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1800573keycloak: missing input validation in IDP authorization URLs

EPSS

Процентиль: 40%
0.00184
Низкий

6.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.4
nvd
больше 5 лет назад

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.

CVSS3: 6.4
debian
больше 5 лет назад

A vulnerability was found in Keycloak before 9.0.2, where every Author ...

github
больше 3 лет назад

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.

EPSS

Процентиль: 40%
0.00184
Низкий

6.4 Medium

CVSS3