CVE-2021-3856: Path Traversal
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
Other sources
https://issues.redhat.com/browse/KEYCLOAK-19422
https://github.com/keycloak/keycloak/blob/master/services/src/main/java/org/keycloak/theme/ClasspathThemeResourceProviderFactory.java
The ThemeResource resource exposes an endpoint for fetching theme resources:
@GET @Path("/{version}/{themeType}/{themeName}/{path:.}") public Response getResource(@PathParam("version") String version, @PathParam("themeType") String themType, @PathParam("themeName") String themeName, @PathParam("path") String path) { ... }
The classbased resource loaders are implemented as:
public InputStream getResourceAsStream(String path) { return classLoader.getResourceAsStream(resourceRoot + path); }
This has no checks for the path parameter, allowing relative traversals like ../.
By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
I practice this exposes any files packages within the deployed module, including other resources available as a classloader resource.
Disallowing double dots in the path component is probably the easiest fix
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-3856?
CVE-2021-3856 is a vulnerability in ClassLoaderTheme and ClasspathThemeResourceProviderFactory that allows reading any file available as a resource to the classloader.
What is the severity of CVE-2021-3856?
CVE-2021-3856 has a severity of medium with a CVSS score of 4.3.
What software is affected by CVE-2021-3856?
Redhat Keycloak versions up to 15.1.0 are affected by CVE-2021-3856.
How can an attacker exploit CVE-2021-3856?
An attacker can exploit CVE-2021-3856 by sending requests for theme resources with a relative path from an external HTTP client, allowing them to receive the content of random files if available.
Is there a fix for CVE-2021-3856?
Yes, upgrading to a version of Redhat Keycloak that is not affected, such as version 15.1.1 or higher, will fix CVE-2021-3856.