Redhat Keycloak vulnerabilities
80 known vulnerabilities affecting redhat/keycloak.
Total CVEs
80
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH29MEDIUM43LOW3
Vulnerabilities
Page 3 of 4
CVE-2024-7341P3HIGHCVSS 7.1≤ 25.0.22024-09-09
CVE-2024-7341 [HIGH] CWE-384 CVE-2024-7341: A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID an
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
nvd
CVE-2022-1466P4MEDIUMCVSS 6.5fixed in 17.0.12022-04-26
CVE-2022-1466 [MEDIUM] CWE-863 CVE-2022-1466: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
nvd
CVE-2023-0264P4MEDIUMCVSS 5.0fixed in 18.0.62023-08-04
CVE-2023-0264 [MEDIUM] CWE-287 CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availabili
nvd
CVE-2021-20262P4MEDIUMCVSS 6.8v12.0.0vKeycloak 12.0.02021-03-09
CVE-2021-20262 [MEDIUM] CWE-306 CVE-2021-20262: A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the passwo
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2020-1758P4MEDIUMCVSS 5.9fixed in 10.0.02020-05-15
CVE-2020-1758 [MEDIUM] CWE-297 CVE-2020-1758: A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname v
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
nvd
CVE-2020-1727P4MEDIUMCVSS 5.4fixed in 9.0.22020-06-22
CVE-2020-1727 [MEDIUM] CWE-20 CVE-2020-1727: A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
nvd
CVE-2024-1722P4MEDIUMCVSS 5.3v23.0.52024-02-29
CVE-2024-1722 [MEDIUM] CWE-645 CVE-2024-1722: A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated a
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
nvd
CVE-2026-0871P4MEDIUMCVSS 4.9fixed in 26.4.02026-02-27
CVE-2026-0871 [MEDIUM] CWE-266 CVE-2026-0871: A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only a
A flaw was found in Keycloak. An administrator with `manage-users` permission can bypass the "Only administrators can view" setting for unmanaged attributes, allowing them to modify these attributes. This improper access control can lead to unauthorized changes to user profiles, even when the system is configured to restrict such modifications.
nvd
CVE-2023-6134P4MEDIUMCVSS 5.4fixed in 22.0.72023-12-14
CVE-2023-6134 [MEDIUM] CWE-79 CVE-2023-6134: A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildc
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
nvd
CVE-2020-35509P4MEDIUMCVSS 5.4v11.0.3v12.0.0+1 more2022-08-23
CVE-2020-35509 [MEDIUM] CWE-20 CVE-2020-35509: A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be a
A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2020-1725P4MEDIUMCVSS 5.4fixed in 13.0.0vkeycloak 13.0.02021-01-28
CVE-2020-1725 [MEDIUM] CWE-863 CVE-2020-1725: A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a r
A flaw was found in keycloak before version 13.0.0. In some scenarios a user still has access to a resource after changing the role mappings in Keycloak and after expiration of the previous access token.
nvd
CVE-2018-10894P4MEDIUMCVSS 5.4v3.4.32018-08-01
CVE-2018-10894 [MEDIUM] CWE-345 CVE-2018-10894: It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired cert
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
nvd
CVE-2017-2585P4MEDIUMCVSS 5.9fixed in 2.5.12018-03-12
CVE-2017-2585 [MEDIUM] CWE-200 CVE-2017-2585: Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that
Red Hat Keycloak before version 2.5.1 has an implementation of HMAC verification for JWS tokens that uses a method that runs in non-constant time, potentially leaving the application vulnerable to timing attacks.
nvd
CVE-2024-7260P4MEDIUMCVSS 6.1fixed in 24.0.72024-09-09
CVE-2024-7260 [MEDIUM] CWE-601 CVE-2024-7260: An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed whe
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into believing that the URL is safe, when, in fact, it redirects to a malicious server. This issue can result
nvd
CVE-2020-1744P4MEDIUMCVSS 5.6fixed in 9.0.12020-03-24
CVE-2020-1744 [MEDIUM] CWE-755 CVE-2020-1744: A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authenticatio
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
nvd
CVE-2018-14655P4MEDIUMCVSS 5.4v3.4.3v4.0.0+1 more2018-11-13
CVE-2018-14655 [MEDIUM] CWE-79 CVE-2018-14655: A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_p
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
nvd
CVE-2022-1274P4MEDIUMCVSS 5.4fixed in 20.0.5vunknown2023-03-29
CVE-2022-1274 [MEDIUM] CWE-80 CVE-2022-1274: A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
nvd
CVE-2021-3461P4HIGHCVSS 7.1v9.0.13vrh-sso7-keycloak 9.0.132022-04-01
CVE-2021-3461 [HIGH] CWE-613 CVE-2021-3461: A flaw was found in keycloak where keycloak may fail to logout user session if the logout request co
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
nvd
CVE-2020-14302P4MEDIUMCVSS 4.9fixed in 13.0.0vkeycloak 13.0.02020-12-15
CVE-2020-14302 [MEDIUM] CWE-294 CVE-2020-14302: A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful aut
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter. This flaw allows a malicious user to perform replay attacks.
nvd
CVE-2020-10748P4MEDIUMCVSS 6.1v10.0.12020-09-16
CVE-2020-10748 [MEDIUM] CWE-79 CVE-2020-10748: A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of da
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
nvd