Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2017-18214 Vulnerability in maven package org.webjars.bowergithub.moment:moment
CVE-2020-14340 Vulnerability in maven package org.jboss.xnio:xnio-nio
CVE-2020-4076 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-3644 Vulnerability in maven package org.wildfly.core:wildfly-controller
CVE-2018-14041 Vulnerability in maven package org.webjars.npm:bootstrap