Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.1 Maven

Keycloak vulnerable to path traversal via double URL encoding

GHSA-g8q8-fggx-9r3q · CVE-2022-3782

Published · Modified

Description

Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes