Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-10770

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.923
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-10770


Contact Us

Shodan ® - All rights reserved