PT-2022-10737 · Red Hat · Keycloak

Paramvir Jindal

·

Published

2022-08-26

·

Updated

2023-07-10

·

CVE-2021-3856

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description The issue concerns ClassLoaderTheme and ClasspathThemeResourceProviderFactory, which allow reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2021-3856
GHSA-3W4V-RVC4-2XPW

Affected Products

Keycloak