Path Traversal Affecting org.keycloak:keycloak-common package, versions [21.1.0,24.0.3)


0.0
high

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
    Confidentiality High
    Integrity High

    Threat Intelligence

    EPSS 0.04% (13th percentile)
Expand this section
Red Hat
8.1 high

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-JAVA-ORGKEYCLOAK-6618056
  • published 18 Apr 2024
  • disclosed 17 Apr 2024
  • credit Axel Flamcourt

How to fix?

Upgrade org.keycloak:keycloak-common to version 24.0.3 or higher.

Overview

org.keycloak:keycloak-common is an Open Source Identity and Access Management For Modern Applications and Services.

Affected versions of this package are vulnerable to Path Traversal due to improper URL validation in the redirection process. An attacker can construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain.

Note: This flaw is particularly concerning for any client that utilizes a wildcard in the Valid Redirect URIs field.

References