Redhat Single Sign-On vulnerabilities

98 known vulnerabilities affecting redhat/single_sign-on.

Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL10HIGH43MEDIUM40LOW5

Vulnerabilities

Page 3 of 5
CVE-2022-2256LOWCVSS 3.8v7.02022-09-01
CVE-2022-2256 [LOW] CWE-79 CVE-2022-2256: A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.
nvd
CVE-2022-1259HIGHCVSS 7.5v7.02022-08-31
CVE-2022-1259 [HIGH] CVE-2022-1259: A flaw was found in Undertow. A potential security issue in flow control handling by the browser ove A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
nvd
CVE-2022-1319HIGHCVSS 7.5v7.02022-08-31
CVE-2022-1319 [HIGH] CWE-252 CVE-2022-1319: A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response pack A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.
nvd
CVE-2021-3632HIGHCVSS 7.5v7.0≥ 7.4, < 7.4.92022-08-26
CVE-2021-3632 [HIGH] CWE-287 CVE-2021-3632: A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
nvd
CVE-2022-0084HIGHCVSS 7.5v7.02022-08-26
CVE-2022-0084 [HIGH] CWE-770 CVE-2022-0084: A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this metho A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
nvd
CVE-2021-3859HIGHCVSS 7.5v7.4.10v7.5.12022-08-26
CVE-2021-3859 [HIGH] CWE-214 CVE-2021-3859: A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.
nvd
CVE-2022-0225MEDIUMCVSS 5.4v7.02022-08-26
CVE-2022-0225 [MEDIUM] CWE-79 CVE-2022-0225: A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
nvd
CVE-2021-3754MEDIUMCVSS 5.3v7.02022-08-26
CVE-2021-3754 [MEDIUM] CWE-20 CVE-2021-3754: A flaw was found in keycloak where an attacker is able to register himself with the username same as A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
nvd
CVE-2021-3827MEDIUMCVSS 6.8v7.0v7.5.02022-08-23
CVE-2021-3827 [MEDIUM] CWE-287 CVE-2021-3827: A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows t A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiali
nvd
CVE-2022-2668HIGHCVSS 7.2v7.02022-08-05
CVE-2022-2668 [HIGH] CVE-2022-2668: An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML pro An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
nvd
CVE-2022-1466MEDIUMCVSS 6.5v7.5.02022-04-26
CVE-2022-1466 [MEDIUM] CWE-863 CVE-2022-1466: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
nvd
CVE-2021-3461HIGHCVSS 7.1v7.0v7.4+1 more2022-04-01
CVE-2021-3461 [HIGH] CWE-613 CVE-2021-3461: A flaw was found in keycloak where keycloak may fail to logout user session if the logout request co A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
nvd
CVE-2022-0853HIGHCVSS 7.5v7.02022-03-11
CVE-2022-0853 [HIGH] CWE-401 CVE-2022-0853: A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client- A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
nvd
CVE-2021-4104HIGHCVSS 7.5v7.02021-12-14
CVE-2021-4104 [HIGH] CWE-502 CVE-2021-4104: JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has wr JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228.
nvd
CVE-2021-3637HIGHCVSS 7.5v7.02021-07-09
CVE-2021-3637 [HIGH] CWE-770 CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticatio A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
nvd
CVE-2021-3424MEDIUMCVSS 5.3v7.42021-06-01
CVE-2021-3424 [MEDIUM] CWE-287 CVE-2021-3424: A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks ar A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
nvd
CVE-2020-27826MEDIUMCVSS 4.2v7.4v7.4.42021-05-28
CVE-2020-27826 [MEDIUM] CWE-250 CVE-2020-27826: A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadat A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
nvd
CVE-2020-10695HIGHCVSS 7.8fixed in 7.4.42021-05-26
CVE-2020-10695 [HIGH] CWE-266 CVE-2020-10695: An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An at An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.
nvd
CVE-2021-20262MEDIUMCVSS 6.8v7.02021-03-09
CVE-2021-20262 [MEDIUM] CWE-306 CVE-2021-20262: A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the passwo A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2020-27838MEDIUMCVSS 6.5PoCv7.02021-03-08
CVE-2020-27838 [MEDIUM] CWE-287 CVE-2020-27838: A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fe A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
nvd