CRITICAL 9.1 Maven
Keycloak vulnerable to path traversal via double URL encoding
GHSA-g8q8-fggx-9r3q · CVE-2022-3782
Published · Modified
Description
Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks.
References
- WEB https://github.com/keycloak/keycloak/security/advisories/GHSA-g8q8-fggx-9r3q
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-3782
- WEB https://github.com/keycloak/keycloak/pull/15982/commits/1987c942f527b9f3bbf2a86ba71ba8ae0154ac37
- WEB https://access.redhat.com/security/cve/CVE-2022-3782
- PACKAGE https://github.com/keycloak/keycloak
Ready to move
Start Securing
Free, no credit card | First findings in minutes