CVE-2020-1727
EUVD-2020-1257522.06.2020, 19:15
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| redhat | keycloak | 𝑥 < 9.0.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration