Input Validation Flaw in Keycloak Affects Identity Provider Server Connections
CVE-2020-1727
6.4MEDIUM
What is CVE-2020-1727?
An input validation vulnerability was discovered in Keycloak versions before 9.0.2, which compromises the security of Authorization URLs. This flaw permits an attacker to incorporate a wide array of characters within deep links, thereby enabling the potential for further assaults on the clients reliant on affected configurations. Proper validation mechanisms should be established to safeguard against these types of exploitation, ensuring the integrity of Identity Provider server interactions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
keycloak Versions before 9.0.2
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
