Description
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6472 | ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available. |
Github GHSA |
GHSA-3w4v-rvc4-2xpw | Keycloak has Files or Directories Accessible to External Parties |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-03T17:09:09.556Z
Reserved: 2021-10-04T00:00:00.000Z
Link: CVE-2021-3856
No data.
Status : Modified
Published: 2022-08-26T16:15:09.570
Modified: 2024-11-21T06:22:39.990
Link: CVE-2021-3856
OpenCVE Enrichment
No data.
EUVD
Github GHSA