Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2023-44402 Vulnerability in npm package electron
CVE-2023-31469 Vulnerability in maven package org.apache.streampipes:streampipes-rest
CVE-2015-7501 Vulnerability in maven package org.apache.commons:commons-collections4
CVE-2023-48796 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master
CVE-2023-29234 Vulnerability in maven package org.apache.dubbo:dubbo