QID 980243
QID 980243: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-xfqh-7356-vqjj)
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xfqh-7356-vqjj for updates pertaining to this vulnerability.
Vendor References
- GHSA-xfqh-7356-vqjj -
github.com/advisories/GHSA-xfqh-7356-vqjj
CVEs related to QID 980243
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xfqh-7356-vqjj | org.keycloak:keycloak-core |
|