Vulnerability record · CVE-2020-10770 · published 15 December 2020
CVE-2020-10770: Keycloak OIDC request_uri parameter enables server-side request forgery
Redhat · Keycloak
Keycloak before 13.0.0 allows the OIDC request_uri parameter to force the server to fetch an unverified URL, resulting in a server-side request forgery (SSRF) flaw. Because the request_uri value is not validated against an allowlist, an unauthenticated remote party can make the Keycloak server issue outbound requests to arbitrary destinations.
Description
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication or user interaction, public exploit code exists, and EPSS is very high, though CVSS impact is limited to low integrity.
What it is
Keycloak before 13.0.0 allows the OIDC request_uri parameter to force the server to fetch an unverified URL, resulting in a server-side request forgery (SSRF) flaw. Because the request_uri value is not validated against an allowlist, an unauthenticated remote party can make the Keycloak server issue outbound requests to arbitrary destinations.
Impact
An attacker can make the Keycloak server send requests to internal or external systems reachable from it, which can expose internal services or metadata endpoints and be used to probe or pivot into the internal network. The CVSS vector rates only low integrity impact and no confidentiality or availability impact, so direct data theft is not established by the record.
Attack surface
Reached over the network through the OIDC authentication endpoint by supplying a crafted request_uri parameter; the CVSS vector shows no privileges required and no user interaction. No authentication is needed to trigger the outbound request.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.697 (99.3rd percentile), and public exploit references exist (Packet Storm, tagged Exploit). No ransomware usage is documented.
What to do
- Upgrade Keycloak to 13.0.0 or later, which is the fixed version named in the advisory.
- If immediate upgrade is not possible, restrict or disable use of the request_uri parameter and validate it against a strict allowlist of trusted URLs.
- Apply network egress controls so the Keycloak server cannot reach internal metadata services, management interfaces, or other sensitive internal hosts.
- Monitor and log outbound requests originating from Keycloak hosts to detect unexpected destinations.
Detection
- Review Keycloak authentication logs for request_uri parameters containing external or internal IP addresses, localhost, or unusual hostnames.
- Monitor outbound network traffic from Keycloak servers for connections to internal RFC1918 addresses, cloud metadata endpoints (169.254.169.254), or unexpected external hosts.
- Alert on repeated or anomalous OIDC authorization requests that include request_uri values, especially from unauthenticated clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/164499/Keycloak-12.0.1-Server-Side-Request-Forgery.html | ExploitThird Party AdvisoryVDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=1846270 | Issue TrackingVendor Advisory |
| http://packetstormsecurity.com/files/164499/Keycloak-12.0.1-Server-Side-Request-Forgery.html | ExploitThird Party AdvisoryVDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=1846270 | Issue TrackingVendor Advisory |
Track CVE-2020-10770 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-10770), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.