Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2022-36897 Vulnerability in maven package com.compuware.jenkins:compuware-xpediter-code-coverage
CVE-2020-8186 Vulnerability in npm package devcert
CVE-2022-28220 Vulnerability in maven package org.apache.james:james-server-protocols-imap4
CVE-2023-24440 Vulnerability in maven package org.jenkins-ci.plugins:jira-steps
CVE-2021-41042 Vulnerability in maven package org.eclipse.lyo:lyo-parent