Description
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14820
Related Vulnerabilities
CVE-2022-29257 Vulnerability in maven package org.webjars.npm:electron
CVE-2021-46708 Vulnerability in npm package swagger-ui
CVE-2021-33040 Vulnerability in npm package epubjs
CVE-2021-23327 Vulnerability in maven package org.webjars.npm:apexcharts
CVE-2017-2608 Vulnerability in maven package org.jenkins-ci.main:jenkins-core