CVEs (112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Keycloak Single Sign OnJun 17, 2026 May 28, 2021 N/A· v4 4.2 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the...Show more |
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges. |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Mar 9, 2021 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s brows...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Mar 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same...Show more |
1Redhat 4Jboss Fuse KeycloakOpenshift Application Runtimes+1 moreJun 17, 2026 Feb 11, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. |
1Redhat 4Jboss Fuse KeycloakOpenshift Application Runtimes+1 moreJun 17, 2026 Feb 11, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are...Show more |
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and o...Show more |
2Netapp Redhat10Active Iq Unified Manager FuseJboss Data Grid+7 moreJun 17, 2026 Nov 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain...Show more |
1Redhat 3Jboss Enterprise Application Platform Openshift Application RuntimesSingle Sign OnJun 17, 2026 Oct 16, 2020 N/A· v4 6.5 MEDIUM· v3 6.3 MEDIUM· v2 A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an at...Show more |
2Netapp Redhat10Data Grid Jboss Data GridJboss Enterprise Application Platform+7 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vuln...Show more |
1Redhat 3Jboss Enterprise Application Platform Single Sign OnUndertowJun 17, 2026 Sep 23, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP...Show more |
1Redhat 2Keycloak Single Sign OnJun 17, 2026 Sep 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks. |
1Redhat 3Keycloak Openshift Application RuntimesSingle Sign OnJun 17, 2026 Sep 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual...Show more |
1Redhat 4Jboss Data Grid Jboss Enterprise Application PlatformOpenshift Application Runtimes+1 moreJun 17, 2026 Sep 16, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400. |
1Redhat 5Amq Jboss Enterprise Application Platform Continuous DeliveryJboss Fuse+2 moreJun 17, 2026 Jul 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received...Show more |
1Redhat 6Amq Jboss Ejb ClientJboss Enterprise Application Platform Continuous Delivery+3 moreJun 17, 2026 Jul 24, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavaila...Show more |
3Hibernate QuarkusRedhat10Build Of Quarkus Decision ManagerFuse+7 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Hibernate ORM in versions before 5.3.18, 5.4.18 and 5.5.0.Beta1. A SQL injection in the implementation of the JPA Criteria API can permit unsanitized literals when a literal is used in the SELECT or G...Show more |
2Netapp Redhat8Active Iq Unified Manager FuseJboss Enterprise Application Platform+5 moreJun 17, 2026 May 26, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling. |
2Quarkus Redhat7Decision Manager Jboss FuseKeycloak+4 moreJun 17, 2026 May 13, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would th...Show more |
1Redhat 3Keycloak Openshift Application RuntimesSingle Sign OnJun 17, 2026 May 11, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section. |