Redhat Keycloak vulnerabilities
80 known vulnerabilities affecting redhat/keycloak.
Total CVEs
80
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH29MEDIUM43LOW3
Vulnerabilities
Page 1 of 4
CVE-2020-10770P2MEDIUMCVSS 5.3ExploitedPoCfixed in 12.0.22020-12-15
CVE-2020-10770 [MEDIUM] CWE-918 CVE-2020-10770: A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
nvd
CVE-2020-27838P3MEDIUMCVSS 6.5PoCfixed in 13.0.0vkeycloak 13.0.02021-03-08
CVE-2020-27838 [MEDIUM] CWE-287 CVE-2020-27838: A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fe
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2021-20323P3MEDIUMCVSS 6.1PoCfixed in 17.0.02022-03-25
CVE-2021-20323 [MEDIUM] CWE-79 CVE-2021-20323: A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
nvd
CVE-2022-3782P3CRITICALCVSS 9.1v20.0.22023-01-13
CVE-2022-3782 [CRITICAL] CWE-22 CVE-2022-3782: keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not pr
keycloak: path traversal via double URL encoding. A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. An attacker can use this flaw to construct a malicious request to bypass validation and access other URLs and potentially sensitive information within the domain or possibly conduct further attacks. This fla
nvd
CVE-2021-4133P3HIGHCVSS 8.8≥ 12.0.0, < 15.1.1vkeycloak 15.1.12022-01-25
CVE-2021-4133 [HIGH] CWE-863 CVE-2021-4133: A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
nvd
CVE-2022-1245P3CRITICALCVSS 9.8fixed in 18.0.0vkeycloak versions prior to 18.0.02022-07-08
CVE-2022-1245 [CRITICAL] CWE-862 CVE-2022-1245: A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorizati
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
nvd
CVE-2020-1714P3HIGHCVSS 8.8fixed in 11.0.02020-05-13
CVE-2020-1714 [HIGH] CWE-20 CVE-2020-1714: A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInp
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
nvd
CVE-2019-14910P3CRITICALCVSS 9.8v7.0.0v7.0.1+1 more2019-12-05
CVE-2019-14910 [CRITICAL] CWE-287 CVE-2019-14910: A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and
A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.
nvd
CVE-2021-20195P3CRITICALCVSS 9.6fixed in 12.0.3vkeycloak 13.0.02021-05-28
CVE-2021-20195 [CRITICAL] CWE-20 CVE-2021-20195: A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating t
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. The highest threat from this vulnerability is to data confidentiality and integrity as well as s
nvd
CVE-2020-1718P3HIGHCVSS 8.8fixed in 8.0.02020-05-12
CVE-2020-1718 [HIGH] CWE-287 CVE-2020-1718: A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allow
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
nvd
CVE-2023-6787P3HIGHCVSS 8.8fixed in 22.0.10≥ 23.0.0, < 24.0.32024-04-25
CVE-2023-6787 [HIGH] CWE-287 CVE-2023-6787: A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "prompt=login," prompting the user to re-enter their credentials. If the user cancels this re-authenticatio
nvd
CVE-2023-4918P3HIGHCVSS 8.8v22.0.22023-09-12
CVE-2023-4918 [HIGH] CWE-256 CVE-2023-4918: A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user re
A flaw was found in the Keycloak package, more specifically org.keycloak.userprofile. When a user registers itself through registration flow, the "password" and "password-confirm" field from the form will occur as regular user attributes. All users and clients with proper rights and roles are able to read users attributes, allowing a malicious user with
nvd
CVE-2019-14837P3CRITICALCVSS 9.1fixed in 8.0.02020-01-07
CVE-2019-14837 [CRITICAL] CWE-547 CVE-2019-14837: A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
nvd
CVE-2024-1132P3HIGHCVSS 8.1≥ 21.1.0, < 22.0.10≥ 23.0.0, < 24.0.32024-04-17
CVE-2024-1132 [HIGH] CWE-22 CVE-2024-1132: A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URI
nvd
CVE-2020-14389P3HIGHCVSS 8.1fixed in 12.0.0vbefore version 12.0.02020-11-17
CVE-2020-14389 [HIGH] CWE-916 CVE-2020-14389: It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
nvd
CVE-2021-3827P3MEDIUMCVSS 6.8fixed in 18.0.0vFixed in v18.0.02022-08-23
CVE-2021-3827 [MEDIUM] CWE-287 CVE-2021-3827: A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows t
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiali
nvd
CVE-2018-14637P3HIGHCVSS 8.1fixed in 4.6.02018-11-30
CVE-2018-14637 [HIGH] CWE-285 CVE-2018-14637: The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditio
The SAML broker consumer endpoint in Keycloak before version 4.6.0.Final ignores expiration conditions on SAML assertions. An attacker can exploit this vulnerability to perform a replay attack.
nvd
CVE-2019-14832P3HIGHCVSS 7.5fixed in 7.0.12019-10-15
CVE-2019-14832 [HIGH] CWE-863 CVE-2019-14832: A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access fro
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured. An authenticated attacker with knowledge of a user id could use this flaw to access unauthorized information or to carry out further attacks.
nvd
CVE-2019-10169P3HIGHCVSS 7.2fixed in 8.0.02020-05-08
CVE-2019-10169 [HIGH] CWE-267 CVE-2019-10169: A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be s
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
nvd
CVE-2019-10170P3HIGHCVSS 7.2fixed in 8.0.02020-05-08
CVE-2019-10170 [HIGH] CWE-267 CVE-2019-10170: A flaw was found in the Keycloak admin console, where the realm management interface permits a scrip
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
nvd
1 / 4Next →