keycloak: path traversal in resources
Published Nov 9, 2020
7.5
HIGHCVSS 3.1
EPSS 1.38%
Description
A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw
Affected products
-
- Version before (excluding) 12.0.0StatusaffectedConstraints-
- Version
No data.
Red Hat Single Sign-On 7.4.3
n/a
Fixed · RHSA-2020:4931
Red Hat Decision Manager 7
keycloak
Not affected
Red Hat Fuse 7
keycloak
Not affected
Red Hat OpenShift Application Runtimes
keycloak
Not affected
Red Hat Process Automation 7
keycloak
Not affected
Red Hat Single Sign-On 7
keyccloak
Affected
Red Hat support for Spring Boot
keycloak
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Single Sign-On 7.4.3 | n/a | Fixed | RHSA-2020:4931 |
| Red Hat Decision Manager 7 | keycloak | Not affected | n/a |
| Red Hat Fuse 7 | keycloak | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | keycloak | Not affected | n/a |
| Red Hat Process Automation 7 | keycloak | Not affected | n/a |
| Red Hat Single Sign-On 7 | keyccloak | Affected | n/a |
| Red Hat support for Spring Boot | keycloak | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:N/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (12 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.38% (0.01377) | 71.11th | v5 (v2026.06.15) |
| Sep 20, 2026 | 1.38% (0.01377) | 70.84th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.17% (0.00172) | 54.60th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.17% (0.00172) | 53.65th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.15% (0.00153) | 49.73th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.89% (0.00885) | 24.24th | v2 (v2022.01.01) |
| Feb 4, 2022 | 9.03% (0.09029) | 86.86th | v2 (v2022.01.01) |
| Feb 3, 2022 | 1.84% (0.01840) | 47.83th | v1 |
| Jan 6, 2022 | 1.84% (0.01840) | 47.32th | v1 |
| Jan 5, 2022 | 0.42% (0.00416) | 26.65th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.42% (0.00416) | 0.00th | v1 |
References (6)
- https://access.redhat.com/security/cve/CVE-2020-14366 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1869764 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14366 x_refsource_CONFIRMIssue TrackingVendor Advisory
- https://github.com/advisories/GHSA-cp67-8w3w-6h9c Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-14366
- https://www.cve.org/CVERecord?id=CVE-2020-14366
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-14366 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1869764 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-14366 | x_refsource_CONFIRMIssue TrackingVendor Advisory | |
| https://github.com/advisories/GHSA-cp67-8w3w-6h9c | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-14366 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-14366 |
Change history (0)
No recorded changes yet.