org.keycloak

174 tracked vulnerabilities.

CVE-2019-10201 HIGH
Keycloak < 6.0.1 - Authentication Bypass via SAML Response Signature Removal
Aug 14, 2019
CVSS 8.1
EPSS 0.00
CVE-2019-10199 HIGH
Keycloak < 6.0.1 - Cross-Site Request Forgery via Inadequate Header Checks
Aug 14, 2019
CVSS 8.8
EPSS 0.00
CVE-2019-3875 MEDIUM
Keycloak < 6.0.2 - Improper Certificate Validation in X.509 Authenticator
Jun 12, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-3868 LOW
Keycloak < 6.0.0 - Session Hijacking via JWT Token
Apr 24, 2019
CVSS 3.8
EPSS 0.00
CVE-2018-14637 MEDIUM
Keycloak <4.6.0.Final - Info Disclosure
Nov 30, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-14658 MEDIUM
JBOSS Keycloak 3.2.1.Final - Open Redirect
Nov 13, 2018
CVSS 6.1
EPSS 0.00
CVE-2018-14657 HIGH
Keycloak 4.2.1.Final, 4.3.0.Final - Improper Restriction of Excessive Authentication Attempts
Nov 13, 2018
CVSS 8.1
EPSS 0.00
CVE-2018-14655 MEDIUM
Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final - Cross-Site Scripting via State Parameter
Nov 13, 2018
CVSS 4.6
EPSS 0.00
CVE-2018-10894 MEDIUM
Keycloak - Improper Certificate Validation in SAML Authentication
Aug 01, 2018
CVSS 5.4
EPSS 0.00
CVE-2018-10912 MEDIUM
Keycloak < 4.0.0 - Authenticated Denial of Service via Session Replacement Infinite Loop
Jul 23, 2018
CVSS 4.9
EPSS 0.00
CVE-2017-2646 HIGH
Keycloak < 2.5.5 - Denial of Service via SAML Logout Request Extension Parsing
Jul 27, 2018
CVSS 7.5
EPSS 0.01
CVE-2017-2582 MEDIUM
Keycloak < 2.5.1 - Information Disclosure via SAML Request ID Field
Jul 26, 2018
CVSS 6.5
EPSS 0.01
CVE-2017-2585 MEDIUM
Red Hat Keycloak < 2.5.1 - Timing Attack via Non-Constant Time HMAC Verification
Mar 12, 2018
CVSS 5.9
EPSS 0.01
CVE-2017-12161 HIGH
Keycloak < 3.4.2 - Password Reset Token Spoofing via Hosts File Manipulation
Feb 21, 2018
CVSS 8.8
EPSS 0.00
CVE-2017-12160 HIGH
Keycloak 0-3.3.0.Final and 3.4.0 - Authenticated Improper Authorization via OAuth Token Pair
Oct 26, 2017
CVSS 7.2
EPSS 0.01
CVE-2017-12159 HIGH
Keycloak - Cross-Site Request Forgery
Oct 26, 2017
CVSS 7.5
EPSS 0.01
CVE-2017-12158 MEDIUM
Keycloak - Reflected XSS
Oct 26, 2017
CVSS 5.4
EPSS 0.01
CVE-2016-8609 LOW
Keycloak < 2.3.0 - Improper Authentication via Phishing URL
Aug 01, 2018
CVSS 3.7
EPSS 0.00
CVE-2016-8629 MEDIUM
Red Hat Keycloak <2.4.0 - Privilege Escalation
Mar 12, 2018
CVSS 6.5
EPSS 0.00
CVE-2014-3652 MEDIUM
Keycloak < 1.1.0.Beta1 - Open Redirect via Unvalidated Redirect URL
Dec 15, 2019
CVSS 6.1
EPSS 0.00
CVE-2014-3656 MEDIUM
JBoss KeyCloak - Cross-Site Scripting in login-status-iframe.html
Dec 10, 2019
CVSS 6.1
EPSS 0.00
CVE-2014-3655 MEDIUM
KeyCloak < 1.0.1 - Cross-Site Request Forgery via Soft Token Deletion
Nov 13, 2019
CVSS 4.3
EPSS 0.00
CVE-2014-3651 HIGH
Keycloak < 1.0.3 - Denial of Service via Large QR Code Size Parameter
Dec 29, 2017
CVSS 7.5
EPSS 0.01
CVE-2014-3709 HIGH
Keycloak < 1.0.3.Final - Cross-Site Request Forgery in SocialResource Callback
Oct 18, 2017
CVSS 8.8
EPSS 0.00