QID 730519
Date Published: 2022-06-15
QID 730519: Keycloak Server-Side Request Forgery (SSRF) Vulnerability
Keycloak is an open source Identity and Access Management solution targeted towards modern applications and services. A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Affected Versions:
Keycloak versions prior to 13.0.0
QID Detection Logic:
This detection sends a specially-crafted GET request with request_uri parameter where vulnerable servers will make a DNS query that will trigger the Qualys Periscope detection mechanism.
Successful exploitation of this vulnerability may allow an remote attacker could exploit this vulnerability to execute a Blind SSRF attack by measuring the response time to perform a port scan of the target server or internally accessible hosts.
- Bugzilla-1846270 -
bugzilla.redhat.com/show_bug.cgi?id=1846270
CVEs related to QID 730519
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Bug 1846270 |
|