Description
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4895 Vulnerability (CVE-2015-4895)
WordPress Plugin Chameleoni Jobs Multiple Cross-Site Scripting Vulnerabilities (1.2.2)
Jboss EAP Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2019-14885)
MySQL CVE-2012-0487 Vulnerability (CVE-2012-0487)
WordPress Plugin SoundCloud Is Gold 'width' Parameter Cross-Site Scripting (2.1)