CVE-2020-14366: Red Hat Keycloak

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw

Affected products

  • Red Hat Keycloak: before 12.0.0 (fixed in 12.0.0)

Published 2020-11-09. Last modified 2026-06-17.