CVE-2020-1727

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/06/2020
Last modified:
07/11/2023

Description

A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:keycloak:*:*:*:*:*:*:*:* 9.0.2 (excluding)


References to Advisories, Solutions, and Tools