CVE-2020-10770

Name
CVE-2020-10770
Description
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Issue Tracking https://bugzilla.redhat.com/show_bug.cgi?id=1846270
Exploit http://packetstormsecurity.com/files/164499/Keycloak-12.0.1-Server-Side-Request-Forgery.html

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* keycloak >= None < 13.0.0
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* keycloak >= None < 12.0.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status