Input validation error in Keycloak - CVE-2020-1727
Published: June 22, 2020 / Updated: July 17, 2020
Keycloak
Keycloak
Description
The vulnerability allows a remote authenticated user to read and manipulate data.
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.