Description
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-0964 | A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw |
Github GHSA |
GHSA-cp67-8w3w-6h9c | Path Traversal |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T12:46:33.307Z
Reserved: 2020-06-17T00:00:00.000Z
Link: CVE-2020-14366
No data.
Status : Modified
Published: 2020-11-09T17:15:12.597
Modified: 2024-11-21T05:03:06.217
Link: CVE-2020-14366
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA