org.keycloak

174 tracked vulnerabilities.

CVE-2024-1722 LOW
Keycloak - Unauthenticated Account Lockout Bypass
Feb 29, 2024
CVSS 3.7
EPSS 0.00
CVE-2023-0657 LOW
Keycloak < 22.0.10 - Authenticated Token Type Confusion via Improper Signature Validation
Nov 17, 2024
CVSS 3.4
EPSS 0.00
CVE-2023-6841 HIGH
Keycloak < 24.0.0 - Denial of Service via Unlimited Attribute Values
Sep 10, 2024
CVSS 7.5
EPSS 0.01
CVE-2023-6787 MEDIUM
Keycloak < 22.0.10 - Authentication Bypass via Re-authentication Mechanism
Apr 25, 2024
CVSS 6.5
EPSS 0.01
CVE-2023-6717 MEDIUM
Keycloak < 22.0.10 - Stored Cross-Site Scripting via SAML Client Registration
Apr 25, 2024
CVSS 6.0
EPSS 0.00
CVE-2023-6544 MEDIUM
Keycloak - Unauthorized Dynamic Client Registration via TrustedDomain Regex
Apr 25, 2024
CVSS 5.4
EPSS 0.01
CVE-2023-6484 MEDIUM
Keycloak < 22.0.9 - Log Injection via WebAuthn Authentication Form
Apr 25, 2024
CVSS 5.3
EPSS 0.01
CVE-2023-3597 MEDIUM
Keycloak < 22.0.10 - Authentication Bypass via Incorrect Client Step-Up Validation
Apr 25, 2024
CVSS 5.0
EPSS 0.00
CVE-2023-6291 HIGH
Keycloak < 22.0.7 and 23.0.0-23.0.2 - Open Redirect via redirect_uri Validation Bypass
Jan 26, 2024
CVSS 7.1
EPSS 0.00
CVE-2023-2585 LOW
Keycloak - Auth Bypass
Dec 21, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-6927 MEDIUM
Keycloak < 23.0.4 - Open Redirect via JARM Response Mode Form Post JWT
Dec 18, 2023
CVSS 4.6
EPSS 0.01
CVE-2023-6134 MEDIUM
Keycloak - Cross-Site Scripting
Dec 14, 2023
CVSS 4.6
EPSS 0.02
CVE-2023-6563 HIGH
Keycloak < 21.0.0 - Unconstrained Memory Consumption via Admin UI Consents Tab
Dec 14, 2023
CVSS 7.7
EPSS 0.01
CVE-2023-2422 MEDIUM
Keycloak < 21.1.2 - Improper Certificate Validation
Oct 04, 2023
CVSS 5.5
EPSS 0.00
CVE-2023-4918 HIGH
Keycloak 22.0.2 - Cleartext Transmission of Sensitive Information via User Registration Form
Sep 12, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-0264 MEDIUM
Keycloak - Authenticated Session Impersonation via OpenID Connect Request Data
Aug 04, 2023
CVSS 5.0
EPSS 0.04
CVE-2023-1664 MEDIUM
Keycloak - Auth Bypass
May 26, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0105 MEDIUM
Keycloak - Improper Authentication via Email Trust Mismanagement
Jan 13, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-0091 LOW
Keycloak - Incorrect Authorization in Client Credential Flow
Jan 13, 2023
CVSS 3.8
EPSS 0.00
CVE-2022-2232 HIGH
Keycloak LDAP Federation < 23.0.1 - LDAP Injection via Username Lookup
Nov 14, 2024
CVSS 7.5
EPSS 0.00
CVE-2022-4137 HIGH
Keycloak < 20.0.5 - Reflected Cross-Site Scripting via OAuth OOB Endpoint
Sep 25, 2023
CVSS 8.1
EPSS 0.01
CVE-2022-3916 MEDIUM
Keycloak < 20.0.2 - Insufficient Session Expiration via Offline Access Scope
Sep 20, 2023
CVSS 6.8
EPSS 0.00
CVE-2022-1438 MEDIUM
Keycloak - Cross-Site Scripting via User Impersonation
Sep 20, 2023
CVSS 6.4
EPSS 0.00
CVE-2022-4361 CRITICAL
Keycloak < 21.1.2 - Cross-Site Scripting via AssertionConsumerServiceURL or redirect_uri
Jul 07, 2023
CVSS 10.0
EPSS 0.01
CVE-2022-1274 MEDIUM
Keycloak < 20.0.5 - Cross-Site Scripting via Execute-Actions-Email Endpoint
Mar 29, 2023
CVSS 5.4
EPSS 0.01