[MAVEN:GHSA-MRV8-PQFJ-7GP5] Keycloak path traversal vulnerability in the redirect validation

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

An issue was found in the redirect_uri validation logic that allows for a bypass of otherwise explicitly allowed hosts.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services >= 23.0.0, < 24.0.3
pkg:maven/org.keycloak/keycloak-services < 22.0.10
ID
MAVEN:GHSA-MRV8-PQFJ-7GP5
Severity
high
URL
https://github.com/advisories/GHSA-mrv8-pqfj-7gp5
Published
2024-04-17T17:31:12
(5 months ago)
Modified
2024-04-17T18:31:33
(5 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services >= 23.0.0 < 24.0.3
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 24.0.3
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 22.0.10
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 22.0.10
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...