A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw
2020-11-09T17:15:12.597
2024-11-21T05:03:06.217
Modified
CVSSv3.1: 6.8 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9