Redhat.Com Keycloak vulnerabilities
2 known vulnerabilities affecting redhat.com/keycloak.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2023-0264MEDIUMCVSS 5.0≥ 18.0.6, < 18.0.62023-08-04
CVE-2023-0264 [MEDIUM] CWE-287 CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availabili
cvelistv5nvd
CVE-2022-3782CRITICALCVSS 9.1≥ 20.0.2, < 20.0.22023-01-13
CVE-2022-3782 [CRITICAL] CWE-22 CVE-2022-3782: keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not pr
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This fla
cvelistv5nvd