Redhat Keycloak vulnerabilities
80 known vulnerabilities affecting redhat/keycloak.
Total CVEs
80
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH29MEDIUM43LOW3
Vulnerabilities
Page 2 of 4
CVE-2020-35509MEDIUMCVSS 5.4v11.0.3v12.0.0+1 more2022-08-23
CVE-2020-35509 [MEDIUM] CWE-20 CVE-2020-35509: A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be a
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2021-3513HIGHCVSS 7.5fixed in 13.0.0vFixed in keycloak v13.0.0.2022-08-22
CVE-2021-3513 [HIGH] CWE-522 CVE-2021-3513: A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2022-2668HIGHCVSS 7.2v18.0.0vKeycloak 182022-08-05
CVE-2022-2668 [HIGH] CVE-2022-2668: An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML pro
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
nvd
CVE-2022-1245CRITICALCVSS 9.8fixed in 18.0.0vkeycloak versions prior to 18.0.02022-07-08
CVE-2022-1245 [CRITICAL] CWE-862 CVE-2022-1245: A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorizati
A privilege escalation flaw was found in the token exchange feature of keycloak. Missing authorization allows a client application holding a valid access token to exchange tokens for any target client by passing the client_id of the target. This could allow a client to gain unauthorized access to additional services.
nvd
CVE-2022-1466MEDIUMCVSS 6.5fixed in 17.0.12022-04-26
CVE-2022-1466 [MEDIUM] CWE-863 CVE-2022-1466: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
nvd
CVE-2021-3461HIGHCVSS 7.1v9.0.13vrh-sso7-keycloak 9.0.132022-04-01
CVE-2021-3461 [HIGH] CWE-613 CVE-2021-3461: A flaw was found in keycloak where keycloak may fail to logout user session if the logout request co
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
nvd
CVE-2021-20323MEDIUMCVSS 6.1PoCfixed in 17.0.02022-03-25
CVE-2021-20323 [MEDIUM] CWE-79 CVE-2021-20323: A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
A POST based reflected Cross Site Scripting vulnerability on has been identified in Keycloak.
nvd
CVE-2021-4133HIGHCVSS 8.8≥ 12.0.0, < 15.1.1vkeycloak 15.1.12022-01-25
CVE-2021-4133 [HIGH] CWE-863 CVE-2021-4133: A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with
A flaw was found in Keycloak in versions from 12.0.0 and before 15.1.1 which allows an attacker with any existing user account to create new default user accounts via the administrative REST API even when new user registration is disabled.
nvd
CVE-2021-3637HIGHCVSS 7.5fixed in 14.0.02021-07-09
CVE-2021-3637 [HIGH] CWE-770 CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticatio
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
nvd
CVE-2021-20195CRITICALCVSS 9.6fixed in 12.0.3vkeycloak 13.0.02021-05-28
CVE-2021-20195 [CRITICAL] CWE-20 CVE-2021-20195: A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating t
A flaw was found in keycloak in versions before 13.0.0. A Self Stored XSS attack vector escalating to a complete account takeover is possible due to user-supplied data fields not being properly encoded and Javascript code being used to process the data. The highest threat from this vulnerability is to data confidentiality and integrity as well as s
nvd
CVE-2020-27826MEDIUMCVSS 4.2fixed in 12.0.0vkeycloak 12.0.02021-05-28
CVE-2020-27826 [MEDIUM] CWE-250 CVE-2020-27826: A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadat
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
nvd
CVE-2021-20202HIGHCVSS 7.3fixed in 13.0.0vkeycloak 13.0.02021-05-12
CVE-2021-20202 [HIGH] CWE-377 CVE-2021-20202: A flaw was found in keycloak. Directories can be created prior to the Java process creating them in
A flaw was found in keycloak. Directories can be created prior to the Java process creating them in the temporary directory, but with wider user permissions, allowing the attacker to have access to the contents that keycloak stores in this directory. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2021-20222HIGHCVSS 7.5≥ 9.0.0, < 13.0.0vkeycloak 13.0.02021-03-23
CVE-2021-20222 [HIGH] CWE-20 CVE-2021-20222: A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be exe
A flaw was found in keycloak. The new account console in keycloak can allow malicious code to be executed using the referrer URL. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-20262MEDIUMCVSS 6.8v12.0.0vKeycloak 12.0.02021-03-09
CVE-2021-20262 [MEDIUM] CWE-306 CVE-2021-20262: A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the passwo
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2020-27838MEDIUMCVSS 6.5PoCfixed in 13.0.0vkeycloak 13.0.02021-03-08
CVE-2020-27838 [MEDIUM] CWE-287 CVE-2020-27838: A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fe
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2020-1717LOWCVSS 2.7v7.0.1vkeycloak 7.0.12021-02-11
CVE-2020-1717 [LOW] CWE-209 CVE-2020-1717: A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
nvd
CVE-2020-1725MEDIUMCVSS 5.4fixed in 13.0.0vkeycloak 13.0.02021-01-28
CVE-2020-1725 [MEDIUM] CWE-863 CVE-2020-1725: A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a r
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
nvd
CVE-2020-14302MEDIUMCVSS 4.9fixed in 13.0.0vkeycloak 13.0.02020-12-15
CVE-2020-14302 [MEDIUM] CWE-294 CVE-2020-14302: A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful aut
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.
nvd
CVE-2020-10770MEDIUMCVSS 5.3PoCfixed in 12.0.22020-12-15
CVE-2020-10770 [MEDIUM] CWE-918 CVE-2020-10770: A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.
nvd
CVE-2020-14389HIGHCVSS 8.1fixed in 12.0.0vbefore version 12.0.02020-11-17
CVE-2020-14389 [HIGH] CWE-916 CVE-2020-14389: It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to
It was found that Keycloak before version 12.0.0 would permit a user with only view-profile role to manage the resources in the new account console, allowing access and modification of data the user was not intended to have.
nvd