Keycloak vulnerable to path traversal via double URL encoding
Critical severity
GitHub Reviewed
Published
Dec 13, 2022
in
keycloak/keycloak
•
Updated Jan 25, 2023
Description
Published to the GitHub Advisory Database
Dec 13, 2022
Reviewed
Dec 13, 2022
Published by the National Vulnerability Database
Jan 13, 2023
Last updated
Jan 25, 2023
Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks.
References