CVE-2022-3782
published 2023-01-13CVE-2022-3782: keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker…
PriorityP356critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
5.80%
92.3th percentile
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat.com | keycloak | >= 20.0.2 < 20.0.2 | 20.0.2 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Keycloak vulnerable to path traversal via double URL encoding
osv·2022-12-13
CVE-2022-3782 [CRITICAL] Keycloak vulnerable to path traversal via double URL encoding
Keycloak vulnerable to path traversal via double URL encoding
Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks.
GHSA
Keycloak vulnerable to path traversal via double URL encoding
ghsa·2022-12-13
CVE-2022-3782 [CRITICAL] CWE-177 Keycloak vulnerable to path traversal via double URL encoding
Keycloak vulnerable to path traversal via double URL encoding
Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks.
Red Hat
keycloak: path traversal via double URL encoding
vendor_redhat·2022-12-12·CVSS 9.1
CVE-2022-3782 [CRITICAL] CWE-22 keycloak: path traversal via double URL encoding
keycloak: path traversal via double URL encoding
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any c
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-01-13
Published