← Back

Single Sign On

single_sign_on

Vendor: Redhat • 112 CVEs

CVEs (112)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
2Keycloak
Single Sign On
Jun 17, 2026
Jun 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a mal...Show more
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.Show less
1Redhat
2Jboss Enterprise Application Platform
Single Sign On
Nov 21, 2024
Mar 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privi...Show more
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.Show less
5Debian
FasterxmlFedoraproject+2 more
11Automation Manager
Debian LinuxDecision Manager+8 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpa...Show more
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.Show less
5Debian
FasterxmlFedoraproject+2 more
11Automation Manager
Debian LinuxDecision Manager+8 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database acce...Show more
An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Nov 13, 2018
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Nov 13, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows...Show more
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Aug 1, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Jul 23, 2018
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious...Show more
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.Show less
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Mar 12, 2018
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.
1Redhat
2Keycloak
Single Sign On
Nov 21, 2024
Mar 12, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw...Show more
Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.Show less
2Keycloak
Redhat
2Keycloak
Single Sign On
May 13, 2026
Oct 26, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosur...Show more
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.Show less
2Keycloak
Redhat
2Keycloak
Single Sign On
May 13, 2026
Oct 26, 2017
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a m...Show more
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.Show less