CVE-2022-3782: Path Traversal
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
Other sources
Keycloak does not properly validate URLs included in a redirect. An attacker could construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain, or possibly conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URIs field.
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-3782.
What is the severity of CVE-2022-3782?
The severity of CVE-2022-3782 is critical with a score of 9.1.
How does CVE-2022-3782 affect Keycloak?
CVE-2022-3782 affects Keycloak by allowing attackers to bypass URL validation and potentially access sensitive information.
Which versions of Keycloak are affected by CVE-2022-3782?
Versions up to and excluding 20.0.2 of Keycloak are affected by CVE-2022-3782.
How can I fix CVE-2022-3782?
To fix CVE-2022-3782, update Keycloak to version 20.0.2 or higher.