QID 150364
Date Published: 2021-09-16
QID 150364: Keycloak SSRF Vulnerability (CVE-2020-10770)
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Affected Versions:
All versions up to 12.0.4
QID Detection Logic:
This detection sends a specially-crafted GET request with request_uri parameter where vulnerable servers will make a DNS query that will trigger the Qualys Periscope detection mechanism.
A remote attacker could exploit this vulnerability to execute a Blind SSRF attack by measuring the response time to perform a port scan of the target server or internally accessible hosts.
Solution
Upgrade to Keycloak 13.0.0 version or later
Vendor References
- Bugzilla - 1846270 -
bugzilla.redhat.com/show_bug.cgi?id=1846270
CVEs related to QID 150364
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Keycloak |
|