Description
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1727
Related Vulnerabilities
CVE-2022-4350 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2015-3250 Vulnerability in maven package org.apache.directory.api:apache-ldap-api
CVE-2019-1003099 Vulnerability in maven package org.jenkins-ci.plugins:openid
CVE-2021-3312 Vulnerability in maven package org.opencms:opencms-core
CVE-2014-9970 Vulnerability in maven package org.jasypt:jasypt