Input Validation Flaw in Keycloak Affects Identity Provider Server Connections
CVE-2020-1727
6.4MEDIUM
What is CVE-2020-1727?
An input validation vulnerability was discovered in Keycloak versions before 9.0.2, which compromises the security of Authorization URLs. This flaw permits an attacker to incorporate a wide array of characters within deep links, thereby enabling the potential for further assaults on the clients reliant on affected configurations. Proper validation mechanisms should be established to safeguard against these types of exploitation, ensuring the integrity of Identity Provider server interactions.
Affected Version(s)
keycloak Versions before 9.0.2
