Skip to content

Known CVE

Keycloak <= 12.0.1 - request_uri Blind Server-Side Request Forgery (SSRF)

Keycloak 12.0.1 and below allows an attacker to force the server to request an unverified URL using the OIDC parameter request_uri. This allows an attacker to execute a server-side request forgery (SSRF) attack.

CVE-2020-10770

Medium2020CVSS 5.3CWE-918

cve2020 · keycloak · ssrf · oast · blind · packetstorm · edb · redhat

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website