PT-2022-24098 · Red Hat · Keycloak

Published

2022-12-13

·

Updated

2023-01-25

·

CVE-2022-3782

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This issue affects any client that utilizes a wildcard in the Valid Redirect URIs field.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-3782
GHSA-G8Q8-FGGX-9R3Q
RHSA-2022:8961
RHSA-2022:8962
RHSA-2022:8963

Affected Products

Keycloak