Lucene search

K
osvGoogleOSV:GHSA-3W4V-RVC4-2XPW
HistoryAug 27, 2022 - 12:00 a.m.

Keycloak has Files or Directories Accessible to External Parties

2022-08-2700:00:45
Google
osv.dev
11
keycloak
files access
directories access
external parties
classloadertheme
classpaththemeresourceproviderfactory
http client
security

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

34.9%

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

4.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

0.001 Low

EPSS

Percentile

34.9%

Related for OSV:GHSA-3W4V-RVC4-2XPW