CVE-2021-3856

MEDIUM

ClassLoaderTheme - Info Disclosure

Title source: llm
STIX 2.1

Description

ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending requests for theme resources with a relative path from an external HTTP client, the client will receive the content of random files if available.

References (5)

Core 5
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://issues.redhat.com/browse/KEYCLOAK-19422
Patch, Third Party Advisory x_refsource_misc
https://github.com/keycloak/keycloak/pull/8588
Issue Tracking, Vendor Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=2010164
Vendor Advisory x_refsource_misc
https://access.redhat.com/security/cve/CVE-2021-3856

Scores

CVSS v3 4.3
EPSS 0.0036
EPSS Percentile 58.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-552 CWE-22
Status published
Products (2)
org.keycloak/keycloak-core 0 - 15.1.0Maven
redhat/keycloak < 15.1.0
Published Aug 26, 2022
Tracked Since Feb 18, 2026