OSV 1.4.0 · github-reviewed · 修改于 2021-04-02 04:31
发布时间
2022-02-09 08:58
GitHub 审查时间
2021-04-02 04:31
NVD 发布时间
2020-11-10 01:15
源文件
advisories/github-reviewed/2022/02/GHSA-cp67-8w3w-6h9c/GHSA-cp67-8w3w-6h9c.json
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw