Количество 4
Количество 4
CVE-2020-10770
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
CVE-2020-10770
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
CVE-2020-10770
A flaw was found in Keycloak before 13.0.0, where it is possible to fo ...
GHSA-jh7q-5mwf-qvhw
Keycloak vulnerable to Server-Side Request Forgery
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2020-10770 A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack. | CVSS3: 5.8 | 92% Критический | около 5 лет назад | |
CVE-2020-10770 A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack. | CVSS3: 5.3 | 92% Критический | около 5 лет назад | |
CVE-2020-10770 A flaw was found in Keycloak before 13.0.0, where it is possible to fo ... | CVSS3: 5.3 | 92% Критический | около 5 лет назад | |
GHSA-jh7q-5mwf-qvhw Keycloak vulnerable to Server-Side Request Forgery | CVSS3: 5.3 | 92% Критический | больше 3 лет назад |
Уязвимостей на страницу