cbcvebase.

Redhat Single Sign-On vulnerabilities

98 known vulnerabilities affecting redhat/single_sign-on.

Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL10HIGH43MEDIUM40LOW5

Vulnerabilities

Page 3 of 5
CVE-2022-0084P3HIGHCVSS 7.5v7.02022-08-26
CVE-2022-0084 [HIGH] CWE-770 CVE-2022-0084: A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this metho A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
nvd
CVE-2023-5379P3HIGHCVSS 7.5v7.02023-12-12
CVE-2023-5379 [HIGH] CWE-770 CVE-2023-5379: A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute A flaw was found in Undertow. When an AJP request is sent that exceeds the max-header-size attribute in ajp-listener, JBoss EAP is marked in an error state by mod_cluster in httpd, causing JBoss EAP to close the TCP connection without returning an AJP response. This happens because mod_proxy_cluster marks the JBoss EAP instance as an error worker when t
nvd
CVE-2020-10695P3HIGHCVSS 7.8fixed in 7.4.42021-05-26
CVE-2020-10695 [HIGH] CWE-266 CVE-2020-10695: An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An at An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.
nvd
CVE-2022-1278P3HIGHCVSS 7.5v7.02022-09-13
CVE-2022-1278 [HIGH] CWE-1188 CVE-2022-1278: A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other da A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.
nvd
CVE-2020-25644P3HIGHCVSS 7.5v7.02020-10-06
CVE-2020-25644 [HIGH] CWE-401 CVE-2020-25644: A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes a A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-14888P3HIGHCVSS 7.5v7.02020-01-23
CVE-2019-14888 [HIGH] CWE-400 CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening o A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
nvd
CVE-2022-1319P3HIGHCVSS 7.5v7.02022-08-31
CVE-2022-1319 [HIGH] CWE-252 CVE-2022-1319: A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response pack A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
nvd
CVE-2021-3637P3HIGHCVSS 7.5v7.02021-07-09
CVE-2021-3637 [HIGH] CWE-770 CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticatio A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
nvd
CVE-2023-6841P3HIGHCVSS 7.5v7.02024-09-10
CVE-2023-6841 [HIGH] CWE-231 CVE-2023-6841: A denial of service vulnerability was found in keycloak where the amount of attributes per object is A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
nvd
CVE-2022-4492P3HIGHCVSS 7.5v7.02023-02-23
CVE-2022-4492 [HIGH] CWE-918 CVE-2022-4492: The undertow client is not checking the server identity presented by the server certificate in https The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.
nvd
CVE-2022-2668P3HIGHCVSS 7.2v7.02022-08-05
CVE-2022-2668 [HIGH] CVE-2022-2668: An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML pro An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
nvd
CVE-2023-6291P3HIGHCVSS 7.1v7.62024-01-26
CVE-2023-6291 [HIGH] CWE-601 CVE-2023-6291: A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful attack may lead to an access token being stolen, making it possible for the attacker to impersonate other users.
nvd
CVE-2023-1664P3MEDIUMCVSS 6.5v7.02023-05-26
CVE-2023-1664 [MEDIUM] CWE-295 CVE-2023-1664: A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Ce A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variabl
nvd
CVE-2022-0853P3HIGHCVSS 7.5v7.02022-03-11
CVE-2022-0853 [HIGH] CWE-401 CVE-2022-0853: A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client- A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
nvd
CVE-2021-3859P3HIGHCVSS 7.5v7.4.10v7.5.12022-08-26
CVE-2021-3859 [HIGH] CWE-214 CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
nvd
CVE-2019-3873P3CRITICALCVSS 9.0v7.02019-06-12
CVE-2019-3873 [CRITICAL] CWE-79 CVE-2019-3873: It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
nvd
CVE-2024-4629P3MEDIUMCVSS 6.5≥ 7.6, < 7.6.102024-09-03
CVE-2024-4629 [MEDIUM] CWE-837 CVE-2024-4629: A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection b A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses
nvd
CVE-2018-14657P3HIGHCVSS 8.1v7.22018-11-13
CVE-2018-14657 [HIGH] CWE-307 CVE-2018-14657: A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
nvd
CVE-2022-1259P3HIGHCVSS 7.5v7.02022-08-31
CVE-2022-1259 [HIGH] CVE-2022-1259: A flaw was found in Undertow. A potential security issue in flow control handling by the browser ove A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
nvd
CVE-2024-7341P3HIGHCVSS 7.1≥ 7.6, < 7.6.102024-09-09
CVE-2024-7341 [HIGH] CWE-384 CVE-2024-7341: A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID an A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who hijacks the current session before authentication to trigger session fixation.
nvd
Redhat Single Sign-On vulnerabilities | cvebase