org.keycloak
174 tracked vulnerabilities.
CVE-2024-1722
LOW
Keycloak - Unauthenticated Account Lockout Bypass
Feb 29, 2024
CVSS 3.7
EPSS 0.00
CVE-2023-0657
LOW
Keycloak < 22.0.10 - Authenticated Token Type Confusion via Improper Signature Validation
Nov 17, 2024
CVSS 3.4
EPSS 0.00
CVE-2023-6841
HIGH
Keycloak < 24.0.0 - Denial of Service via Unlimited Attribute Values
Sep 10, 2024
CVSS 7.5
EPSS 0.01
CVE-2023-6787
MEDIUM
Keycloak < 22.0.10 - Authentication Bypass via Re-authentication Mechanism
Apr 25, 2024
CVSS 6.5
EPSS 0.01
CVE-2023-6717
MEDIUM
Keycloak < 22.0.10 - Stored Cross-Site Scripting via SAML Client Registration
Apr 25, 2024
CVSS 6.0
EPSS 0.00
CVE-2023-6544
MEDIUM
Keycloak - Unauthorized Dynamic Client Registration via TrustedDomain Regex
Apr 25, 2024
CVSS 5.4
EPSS 0.01
CVE-2023-6484
MEDIUM
Keycloak < 22.0.9 - Log Injection via WebAuthn Authentication Form
Apr 25, 2024
CVSS 5.3
EPSS 0.01
CVE-2023-3597
MEDIUM
Keycloak < 22.0.10 - Authentication Bypass via Incorrect Client Step-Up Validation
Apr 25, 2024
CVSS 5.0
EPSS 0.00
CVE-2023-6291
HIGH
Keycloak < 22.0.7 and 23.0.0-23.0.2 - Open Redirect via redirect_uri Validation Bypass
Jan 26, 2024
CVSS 7.1
EPSS 0.00
CVE-2023-2585
LOW
Keycloak - Auth Bypass
Dec 21, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-6927
MEDIUM
Keycloak < 23.0.4 - Open Redirect via JARM Response Mode Form Post JWT
Dec 18, 2023
CVSS 4.6
EPSS 0.01
CVE-2023-6134
MEDIUM
Keycloak - Cross-Site Scripting
Dec 14, 2023
CVSS 4.6
EPSS 0.02
CVE-2023-6563
HIGH
Keycloak < 21.0.0 - Unconstrained Memory Consumption via Admin UI Consents Tab
Dec 14, 2023
CVSS 7.7
EPSS 0.01
CVE-2023-2422
MEDIUM
Keycloak < 21.1.2 - Improper Certificate Validation
Oct 04, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-4918
HIGH
Keycloak 22.0.2 - Cleartext Transmission of Sensitive Information via User Registration Form
Sep 12, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-0264
MEDIUM
Keycloak - Authenticated Session Impersonation via OpenID Connect Request Data
Aug 04, 2023
CVSS 5.0
EPSS 0.04
CVE-2023-1664
MEDIUM
Keycloak - Auth Bypass
May 26, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0105
MEDIUM
Keycloak - Improper Authentication via Email Trust Mismanagement
Jan 13, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0091
LOW
Keycloak - Incorrect Authorization in Client Credential Flow
Jan 13, 2023
CVSS 3.8
EPSS 0.00
CVE-2022-2232
HIGH
Keycloak LDAP Federation < 23.0.1 - LDAP Injection via Username Lookup
Nov 14, 2024
CVSS 7.5
EPSS 0.00
CVE-2022-4137
HIGH
Keycloak < 20.0.5 - Reflected Cross-Site Scripting via OAuth OOB Endpoint
Sep 25, 2023
CVSS 8.1
EPSS 0.01
CVE-2022-3916
MEDIUM
Keycloak < 20.0.2 - Insufficient Session Expiration via Offline Access Scope
Sep 20, 2023
CVSS 6.8
EPSS 0.00
CVE-2022-1438
MEDIUM
Keycloak - Cross-Site Scripting via User Impersonation
Sep 20, 2023
CVSS 6.4
EPSS 0.00
CVE-2022-4361
CRITICAL
Keycloak < 21.1.2 - Cross-Site Scripting via AssertionConsumerServiceURL or redirect_uri
Jul 07, 2023
CVSS 10.0
EPSS 0.01
CVE-2022-1274
MEDIUM
Keycloak < 20.0.5 - Cross-Site Scripting via Execute-Actions-Email Endpoint
Mar 29, 2023
CVSS 5.4
EPSS 0.01
Products
keycloak-services 74
keycloak-core 48
keycloak-parent 25
keycloak-quarkus-server 9
keycloak-server-spi-private 5
keycloak-ldap-federation 4
keycloak-saml-core 4
keycloak-model-jpa 3
keycloak-saml-adapter-core 3
keycloak-model-infinispan 2
keycloak-quarkus-dist 2
keycloak-account-ui 1
keycloak-adapter-core 1
keycloak-admin-ui 1
keycloak-authz-client 1
keycloak-broker-saml 1
keycloak-common 1
keycloak-js-admin-client 1
keycloak-model-storage-services 1
keycloak-oidc-client-adapter-pom 1
Quick Filters