CVEs (112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security pat...Show more |
429bis ApacheApple+39 more68Advanced Cluster Security AsyncsshCeph Storage+65 moreJun 17, 2026 Dec 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negoti...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Power+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Dec 14, 2023 N/A· v4 7.7 HIGH· v3 N/A· v2 An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an...Show more |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnUndertowJun 17, 2026 Dec 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP conn...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Oct 4, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can a...Show more |
1Redhat 7Jboss Enterprise Application Platform Jboss Enterprise Application Platform Text Only AdvisoriesOpenshift Container Platform+4 moreJun 17, 2026 Sep 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If th...Show more |
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. Th...Show more |
1Redhat 5Openshift Container Platform Openshift Container Platform For Ibm ZOpenshift Container Platform For Linuxone+2 moreJun 17, 2026 Sep 22, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code...Show more |
1Redhat 6Keycloak Openshift Container PlatformOpenshift Container Platform For Linuxone+3 moreJun 17, 2026 Sep 20, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session...Show more |
2Netapp Redhat16Build Of Quarkus Decision ManagerFuse+13 moreJun 17, 2026 Sep 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Aug 4, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use th...Show more |
1Redhat 5Keycloak Openshift Container PlatformOpenshift Container Platform For Ibm Linuxone+2 moreJun 17, 2026 Jul 7, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by sett...Show more |
1Redhat 5Build Of Quarkus Jboss A MqKeycloak+2 moreJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an a...Show more |
1Redhat 3Keycloak Openshift Container PlatformSingle Sign OnJun 17, 2026 Mar 29, 2023 N/A· v4 5.4 MEDIUM· v3 N/A· v2 A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users...Show more |
1Redhat 2Keycloak Node.js Adapter Single Sign OnJun 17, 2026 Mar 27, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function. |
1Redhat 10Build Of Quarkus Integration Camel For Spring BootIntegration Camel K+7 moreJun 17, 2026 Feb 23, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add...Show more |
1Redhat 8Amq Amq OnlineIntegration Camel K+5 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain. |
2Netapp Redhat9Active Iq Unified Manager Cloud Secure AgentIntegration Camel K+6 moreJun 17, 2026 Sep 1, 2022 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. |