Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2026-3872

4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2026-3872

4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2026-3872

4 месяца назад

A flaw was found in Keycloak. This issue allows an attacker, who contr ...

CVSS3: 7.3
EPSS: Низкий
github логотип

GHSA-cjm2-j6cm-6p6m

4 месяца назад

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect Uniform Resource Identifiers (URIs) that use a wildcard. A successful attack may lead to the theft of an access token, resulting in information disclosure.

CVSS3: 7.3
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who contr ...

CVSS3: 7.3
0%
Низкий
4 месяца назад
github логотип
GHSA-cjm2-j6cm-6p6m

Keycloak: Redirect URI validation bypass via ..;/ path traversal in OIDC auth endpoint

CVSS3: 7.3
0%
Низкий
4 месяца назад

Уязвимостей на страницу