A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
2020-06-22T19:15:10.717
2024-11-21T05:11:15.170
Modified
CVSSv3.1: 6.4 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:P/A:N
8.0
4.9