Loading HuntDB...

GHSA-3w4v-rvc4-2xpw

GitHub Security Advisory

Keycloak has Files or Directories Accessible to External Parties

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

Affected Packages

Maven org.keycloak:keycloak-core
Affected versions: 0 (fixed in 15.1.0)

Related CVEs

Key Information

GHSA ID
GHSA-3w4v-rvc4-2xpw
Published
August 27, 2022 12:00 AM
Last Modified
September 2, 2022 9:12 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.keycloak:keycloak-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 31, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.