Redhat Single Sign-On vulnerabilities
98 known vulnerabilities affecting redhat/single_sign-on.
Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL10HIGH43MEDIUM40LOW5
Vulnerabilities
Page 2 of 5
CVE-2019-14837P3CRITICALCVSS 9.1v7.32020-01-07
CVE-2019-14837 [CRITICAL] CWE-547 CVE-2019-14837: A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup
A flaw was found in keycloack before version 8.0.0. The owner of 'placeholder.org' domain can setup mail server on this domain and knowing only name of a client can reset password and then log in. For example, for client name 'test' the email address will be '[email protected]'.
nvd
CVE-2025-9784P3HIGHCVSS 7.5v7.02025-09-02
CVE-2025-9784 [HIGH] CWE-770 CVE-2025-9784: A flaw was found in Undertow where malformed client requests can trigger server-side stream resets w
A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, this highlights a common implem
nvd
CVE-2026-3121P3HIGHCVSS 7.2v7.02026-03-26
CVE-2026-3121 [HIGH] CWE-266 CVE-2026-3121: A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a miscon
A flaw was found in Keycloak. An administrator with `manage-clients` permission can exploit a misconfiguration where this permission is equivalent to `manage-permissions`. This allows the administrator to escalate privileges and gain control over roles, users, or other administrative functions within the realm. This privilege escalation can occur when a
nvd
CVE-2019-14887P3CRITICALCVSS 9.1v7.02020-03-16
CVE-2019-14887 [CRITICAL] CWE-757 CVE-2019-14887: A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' val
A flaw was found when an OpenSSL security provider is used with Wildfly, the 'enabled-protocols' value in the Wildfly configuration isn't honored. An attacker could target the traffic sent from Wildfly and downgrade the connection to a weaker version of TLS, potentially breaking the encryption. This could lead to a leak of the data being passed ov
nvd
CVE-2020-1757P3HIGHCVSS 8.1v7.02020-04-21
CVE-2020-1757 [HIGH] CWE-20 CVE-2020-1757: A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
nvd
CVE-2024-1132P3HIGHCVSS 8.1v7.62024-04-17
CVE-2024-1132 [HIGH] CWE-22 CVE-2024-1132: A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that utilizes a wildcard in the Valid Redirect URI
nvd
CVE-2024-1635P3HIGHCVSS 7.5v7.62024-02-19
CVE-2024-1635 [HIGH] CWE-400 CVE-2024-1635: A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly
A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end with both memory and open file limits exhausted at some point, depending on the
nvd
CVE-2021-3827P3MEDIUMCVSS 6.8v7.0v7.5.02022-08-23
CVE-2021-3827 [MEDIUM] CWE-287 CVE-2021-3827: A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows t
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiali
nvd
CVE-2019-10184P3HIGHCVSS 7.5v7.0v7.32019-07-25
CVE-2019-10184 [HIGH] CWE-862 CVE-2019-10184: undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have t
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
nvd
CVE-2024-7885P3HIGHCVSS 7.5v7.02024-08-21
CVE-2024-7885 [HIGH] CWE-362 CVE-2024-7885: A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuil
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder instance, potentially leading to inform
nvd
CVE-2023-3223P3HIGHCVSS 7.5v7.62023-09-27
CVE-2023-3223 [HIGH] CWE-789 CVE-2023-3223: A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to nu
nvd
CVE-2020-14299P3MEDIUMCVSS 6.5v7.02020-10-16
CVE-2020-14299 [MEDIUM] CWE-287 CVE-2020-14299: A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy Secur
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using an arbitrary user and password. The highest threat to vulnerability is
nvd
CVE-2019-10201P3HIGHCVSS 8.1v7.0v7.3.32019-08-14
CVE-2019-10201 [HIGH] CWE-592 CVE-2019-10201: It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signa
It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message signatures. If an attacker modifies the SAML Response and removes the sections, the message is still accepted, and the message can be modified. An attacker could use this flaw to impersonate other users and gain access to sensitive information.
nvd
CVE-2022-3916P3MEDIUMCVSS 6.8v7.62023-09-20
CVE-2022-3916 [MEDIUM] CWE-384 CVE-2022-3916: A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared co
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user authentication sessions. This enables an attacker to resolve a user session attached to a previously authen
nvd
CVE-2020-10758P3HIGHCVSS 7.5v7.0v7.42020-09-16
CVE-2020-10758 [HIGH] CWE-770 CVE-2020-10758: A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty r
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
nvd
CVE-2023-6563P3HIGHCVSS 7.7v7.62023-12-14
CVE-2023-6563 [HIGH] CWE-770 CVE-2023-6563: An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge
nvd
CVE-2021-3632P3HIGHCVSS 7.5v7.0≥ 7.4, < 7.4.92022-08-26
CVE-2021-3632 [HIGH] CWE-287 CVE-2021-3632: A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
nvd
CVE-2026-3260P3HIGHCVSS 7.5v7.02026-03-24
CVE-2026-3260 [HIGH] CWE-770 CVE-2026-3260: A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending an HTTP GET request containing multipart/form-data content. If the underlying application processes parameters using methods like `getParameterMap()`, the server prematurely parses and stores this content to disk. This could lead to resource exhaustion, potentiall
nvd
CVE-2023-2422P3HIGHCVSS 7.1v7.62023-10-04
CVE-2023-2422 [HIGH] CWE-295 CVE-2023-2422: A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
nvd
CVE-2023-1108P3HIGHCVSS 7.5v7.62023-09-14
CVE-2023-1108 [HIGH] CWE-835 CVE-2023-1108: A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unex
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
nvd