cbcvebase.

Redhat Keycloak vulnerabilities

80 known vulnerabilities affecting redhat/keycloak.

Total CVEs
80
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH29MEDIUM43LOW3

Vulnerabilities

Page 2 of 4
CVE-2019-10199P3HIGHCVSS 8.8≤ 6.0.12019-08-14
CVE-2019-10199 [HIGH] CWE-352 CVE-2019-10199: It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
nvd
CVE-2019-10201P3HIGHCVSS 8.1≤ 6.0.12019-08-14
CVE-2019-10201 [HIGH] CWE-592 CVE-2019-10201: It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signa It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
nvd
CVE-2020-14366P3HIGHCVSS 7.5fixed in 12.0.02020-11-09
CVE-2020-14366 [HIGH] CWE-22 CVE-2020-14366: A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the r A vulnerability was found in keycloak, where path traversal using URL-encoded path segments in the request is possible because the resources endpoint applies a transformation of the url path to the file path. Only few specific folder hierarchies can be exposed by this flaw
nvd
CVE-2022-3916P3MEDIUMCVSS 6.8fixed in 20.0.22023-09-20
CVE-2022-3916 [MEDIUM] CWE-384 CVE-2022-3916: A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared co A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authen
nvd
CVE-2020-10758P3HIGHCVSS 7.5fixed in 11.0.1vKeycloak before 11.0.12020-09-16
CVE-2020-10758 [HIGH] CWE-770 CVE-2020-10758: A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty r A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
nvd
CVE-2023-6563P3HIGHCVSS 7.7fixed in 21.0.02023-12-14
CVE-2023-6563 [HIGH] CWE-770 CVE-2023-6563: An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge
nvd
CVE-2021-20222P3HIGHCVSS 7.5≥ 9.0.0, < 13.0.0vkeycloak 13.0.02021-03-23
CVE-2021-20222 [HIGH] CWE-20 CVE-2021-20222: A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be exe A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-3632P3HIGHCVSS 7.5fixed in 15.1.0vFixed in v15.1.02022-08-26
CVE-2021-3632 [HIGH] CWE-287 CVE-2021-3632: A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
nvd
CVE-2021-20202P3HIGHCVSS 7.3fixed in 13.0.0vkeycloak 13.0.02021-05-12
CVE-2021-20202 [HIGH] CWE-377 CVE-2021-20202: A flaw was found in keycloak. Directories can be created prior to the Java process creating them in A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2016-8609P3HIGHCVSS 8.1fixed in 2.3.02018-08-01
CVE-2016-8609 [HIGH] CWE-384 CVE-2016-8609: It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An atta It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.
nvd
CVE-2021-3513P3HIGHCVSS 7.5fixed in 13.0.0vFixed in keycloak v13.0.0.2022-08-22
CVE-2021-3513 [HIGH] CWE-522 CVE-2021-3513: A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2016-8629P3MEDIUMCVSS 6.5fixed in 2.4.02018-03-12
CVE-2016-8629 [MEDIUM] CWE-284 CVE-2016-8629: Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service acco Red Hat Keycloak before version 2.4.0 did not correctly check permissions when handling service account user deletion requests sent to the rest server. An attacker with service account authentication could use this flaw to bypass normal permissions and delete users in a separate realm.
nvd
CVE-2019-14909P3HIGHCVSS 8.3v7.0.0v7.0.1+1 more2019-12-04
CVE-2019-14909 [HIGH] CWE-287 CVE-2019-14909: A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP ano A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
nvd
CVE-2021-3637P3HIGHCVSS 7.5fixed in 14.0.02021-07-09
CVE-2021-3637 [HIGH] CWE-770 CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticatio A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
nvd
CVE-2022-2668P3HIGHCVSS 7.2v18.0.0vKeycloak 182022-08-05
CVE-2022-2668 [HIGH] CVE-2022-2668: An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML pro An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
nvd
CVE-2023-6291P3HIGHCVSS 7.1fixed in 22.0.72024-01-26
CVE-2023-6291 [HIGH] CWE-601 CVE-2023-6291: A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
nvd
CVE-2017-2646P3HIGHCVSS 7.5fixed in 2.5.52018-07-27
CVE-2017-2646 [HIGH] CWE-835 CVE-2017-2646: It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the midd It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.
nvd
CVE-2024-4629P3MEDIUMCVSS 6.5fixed in 24.0.32024-09-03
CVE-2024-4629 [MEDIUM] CWE-837 CVE-2024-4629: A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection b A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses
nvd
CVE-2018-14657P3HIGHCVSS 8.1v4.2.1v4.3.02018-11-13
CVE-2018-14657 [HIGH] CWE-307 CVE-2018-14657: A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
nvd
CVE-2017-2582P4MEDIUMCVSS 6.5fixed in 2.5.12018-07-26
CVE-2017-2582 [MEDIUM] CWE-201 CVE-2017-2582: It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by formatting the SAML request ID field to be the chosen system property which coul
nvd
Redhat Keycloak vulnerabilities | cvebase