CVE Database
/

CVE-2021-3856

Back to search

CVE-2021-3856

Published: Aug 26, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

VendorProductVersions

n/a

keycloak

affected
Fixed in 15.1.0

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now