Keycloak has Files or Directories Accessible to External Parties
Moderate severity
GitHub Reviewed
Published
Aug 27, 2022
to the GitHub Advisory Database
•
Updated Jul 11, 2023
Description
Published by the National Vulnerability Database
Aug 26, 2022
Published to the GitHub Advisory Database
Aug 27, 2022
Reviewed
Sep 2, 2022
Last updated
Jul 11, 2023
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
References