GHSA-3w4v-rvc4-2xpw
GitHub Security Advisory
Keycloak has Files or Directories Accessible to External Parties
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.
Affected Packages
Maven
org.keycloak:keycloak-core
Affected versions:
0
(fixed in 15.1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 31, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.