CVEs (112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Jun 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a mal...Show more |
1Redhat 2Jboss Enterprise Application Platform Single Sign OnNov 21, 2024 Mar 27, 2019 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privi...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpa...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database acce...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Nov 13, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures. |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Nov 13, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Aug 1, 2018 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks. |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Jul 23, 2018 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious...Show more |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Mar 12, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks. |
1Redhat 2Keycloak Single Sign OnNov 21, 2024 Mar 12, 2018 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw...Show more |
2Keycloak Redhat2Keycloak Single Sign OnMay 13, 2026 Oct 26, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosur...Show more |
2Keycloak Redhat2Keycloak Single Sign OnMay 13, 2026 Oct 26, 2017 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a m...Show more |