Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2019-10295 Vulnerability in maven package org.jenkins-ci.plugins:crittercism-dsym
CVE-2023-37478 Vulnerability in npm package @pnpm/win-x64
CVE-2021-21380 Vulnerability in maven package org.xwiki.platform:xwiki-platform-ratings-api
CVE-2020-35509 Vulnerability in maven package org.keycloak:keycloak-services
CVE-2020-5408 Vulnerability in maven package org.springframework.security:spring-security-core