org.keycloak:keycloak-common@23.0.1 vulnerabilities
-
latest version
26.0.4
-
latest non vulnerable version
-
first published
9 years ago
-
latest version published
21 days ago
-
licenses detected
- [1.6.0.Final,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.keycloak:keycloak-common package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.keycloak:keycloak-common is an Open Source Identity and Access Management For Modern Applications and Services. Affected versions of this package are vulnerable to Path Traversal due to improper URL validation in the redirection process. An attacker can construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain. Note: This flaw is particularly concerning for any client that utilizes a wildcard in the Valid Redirect URIs field. How to fix Path Traversal? Upgrade |
[21.1.0,24.0.3)
|
org.keycloak:keycloak-common is an Open Source Identity and Access Management For Modern Applications and Services. Affected versions of this package are vulnerable to Open Redirect due to improper validation of redirect URIs using the How to fix Open Redirect? Upgrade |
[,23.0.4)
|