Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2022-29251 Vulnerability in maven package org.xwiki.platform:xwiki-platform-flamingo-theme-ui
CVE-2020-11023 Vulnerability in maven package org.webjars.bowergithub.jquery:jquery
CVE-2023-34238 Vulnerability in npm package gatsby-plugin-mdx
CVE-2022-24697 Vulnerability in maven package org.apache.kylin:kylin-server-base
CVE-2022-26850 Vulnerability in maven package org.apache.nifi:nifi-single-user-utils