Vulnerabilities > CVE-2020-10770 - Server-Side Request Forgery (SSRF) vulnerability in Redhat Keycloak

047910
CVSS 5.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
LOW
Availability impact
NONE
network
low complexity
redhat
CWE-918

Summary

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

Vulnerable Configurations

Part Description Count
Application
Redhat
121

Common Weakness Enumeration (CWE)