#VU70169 Path traversal in Keycloak - CVE-2022-3782
Published: December 13, 2022
Keycloak
Keycloak
Description
The vulnerability allows a remote attacker to perform path traversal attacks.
The vulnerability exists due to insufficient validation of URLs included in a redirect. A remote attacker can construct a malicious request to bypass validation by using double encoding, access other URLs and potentially sensitive information within the domain.