Количество 4
Количество 4
CVE-2022-3782
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
CVE-2022-3782
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
CVE-2022-3782
keycloak: path traversal via double URL encoding. A flaw was found in ...
GHSA-g8q8-fggx-9r3q
Keycloak vulnerable to path traversal via double URL encoding
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2022-3782 keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field. | CVSS3: 8.1 | 0% Низкий | около 3 лет назад | |
CVE-2022-3782 keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field. | CVSS3: 9.1 | 0% Низкий | около 3 лет назад | |
CVE-2022-3782 keycloak: path traversal via double URL encoding. A flaw was found in ... | CVSS3: 9.1 | 0% Низкий | около 3 лет назад | |
GHSA-g8q8-fggx-9r3q Keycloak vulnerable to path traversal via double URL encoding | CVSS3: 9.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу