Redhat Single Sign-On vulnerabilities
98 known vulnerabilities affecting redhat/single_sign-on.
Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL10HIGH43MEDIUM40LOW5
Vulnerabilities
Page 4 of 5
CVE-2020-14307P4MEDIUMCVSS 6.5v7.02020-07-24
CVE-2020-14307 [MEDIUM] CWE-404 CVE-2020-14307: A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBo
A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows an attacker to craft a denial of service attack to make the service unav
nvd
CVE-2022-1466P4MEDIUMCVSS 6.5v7.5.02022-04-26
CVE-2022-1466 [MEDIUM] CWE-863 CVE-2022-1466: Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
nvd
CVE-2026-4366P4MEDIUMCVSS 5.8v7.02026-03-18
CVE-2026-4366 [MEDIUM] CWE-918 CVE-2026-4366: A flaw was identified in Keycloak, an identity and access management solution, where it improperly f
A flaw was identified in Keycloak, an identity and access management solution, where it improperly follows HTTP redirects when processing certain client configuration requests. This behavior allows an attacker to trick the server into making unintended requests to internal or restricted resources. As a result, sensitive internal services such as cloud
nvd
CVE-2020-25689P4MEDIUMCVSS 6.5v7.02020-11-02
CVE-2020-25689 [MEDIUM] CWE-401 CVE-2020-25689: A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tr
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a denial of service. The highest threat
nvd
CVE-2023-6927P4MEDIUMCVSS 6.1v7.02023-12-18
CVE-2023-6927 [MEDIUM] CVE-2023-6927: A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or token
A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM response mode "form_post.jwt" which could be used to bypass the security patch implemented to address CVE-2023-6134.
nvd
CVE-2023-0264P4MEDIUMCVSS 5.0fixed in 7.6.22023-08-04
CVE-2023-0264 [MEDIUM] CWE-287 CVE-2023-0264: A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the victim and generate new session tokens. This issue could impact confidentiality, integrity, and availabili
nvd
CVE-2020-14297P4MEDIUMCVSS 6.5v7.02020-07-24
CVE-2020-14297 [MEDIUM] CWE-400 CVE-2020-14297: A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specif
A flaw was discovered in Wildfly's EJB Client as shipped with Red Hat JBoss EAP 7, where some specific EJB transaction objects may get accumulated over the time and can cause services to slow down and eventaully unavailable. An attacker can take advantage and cause denial of service attack and make services unavailable.
nvd
CVE-2021-20262P4MEDIUMCVSS 6.8v7.02021-03-09
CVE-2021-20262 [MEDIUM] CWE-306 CVE-2021-20262: A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the passwo
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2023-6134P4MEDIUMCVSS 5.4fixed in 7.62023-12-14
CVE-2023-6134 [MEDIUM] CWE-79 CVE-2023-6134: A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildc
A flaw was found in Keycloak that prevents certain schemes in redirects, but permits them if a wildcard is appended to the token. This issue could allow an attacker to submit a specially crafted request leading to cross-site scripting (XSS) or further attacks. This flaw is the result of an incomplete fix for CVE-2020-10748.
nvd
CVE-2022-0225P4MEDIUMCVSS 5.4v7.02022-08-26
CVE-2022-0225 [MEDIUM] CWE-79 CVE-2022-0225: A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as
A flaw was found in Keycloak. This flaw allows a privileged attacker to use the malicious payload as the group name while creating a new group from the admin console, leading to a stored Cross-site scripting (XSS) attack.
nvd
CVE-2018-10894P4MEDIUMCVSS 5.4v7.22018-08-01
CVE-2018-10894 [MEDIUM] CWE-345 CVE-2018-10894: It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired cert
It was found that SAML authentication in Keycloak 3.4.3.Final incorrectly authenticated expired certificates. A malicious user could use this to access unauthorized data or possibly conduct further attacks.
nvd
CVE-2021-3754P4MEDIUMCVSS 5.3v7.02022-08-26
CVE-2021-3754 [MEDIUM] CWE-20 CVE-2021-3754: A flaw was found in keycloak where an attacker is able to register himself with the username same as
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
nvd
CVE-2018-14655P4MEDIUMCVSS 5.4v7.22018-11-13
CVE-2018-14655 [MEDIUM] CWE-79 CVE-2018-14655: A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_p
A flaw was found in Keycloak 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final. When using 'response_mode=form_post' it is possible to inject arbitrary Javascript-Code via the 'state'-parameter in the authentication URL. This allows an XSS-Attack upon succesfully login.
nvd
CVE-2022-1274P4MEDIUMCVSS 5.4≥ 7.6, < 7.6.22023-03-29
CVE-2022-1274 [MEDIUM] CWE-80 CVE-2022-1274: A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
nvd
CVE-2021-3424P4MEDIUMCVSS 5.3v7.42021-06-01
CVE-2021-3424 [MEDIUM] CWE-287 CVE-2021-3424: A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks ar
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
nvd
CVE-2021-3461P4HIGHCVSS 7.1v7.0v7.4+1 more2022-04-01
CVE-2021-3461 [HIGH] CWE-613 CVE-2021-3461: A flaw was found in keycloak where keycloak may fail to logout user session if the logout request co
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
nvd
CVE-2022-4137P4MEDIUMCVSS 6.1v7.62023-09-25
CVE-2022-4137 [MEDIUM] CWE-81 CVE-2022-4137: A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to in
A reflected cross-site scripting (XSS) vulnerability was found in the 'oob' OAuth endpoint due to incorrect null-byte handling. This issue allows a malicious link to insert an arbitrary URI into a Keycloak error page. This flaw requires a user or administrator to interact with a link in order to be vulnerable. This may compromise user details, allowing
nvd
CVE-2020-10748P4MEDIUMCVSS 6.1fixed in 7.4.12020-09-16
CVE-2020-10748 [MEDIUM] CWE-79 CVE-2020-10748: A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of da
A flaw was found in Keycloak's data filter, in version 10.0.1, where it allowed the processing of data URLs in some circumstances. This flaw allows an attacker to conduct cross-site scripting or further attacks.
nvd
CVE-2023-1932P4MEDIUMCVSS 6.1v7.02024-11-07
CVE-2023-1932 [MEDIUM] CWE-79 CVE-2023-1932: A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.c
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
nvd
CVE-2022-4361P4MEDIUMCVSS 6.1≥ 7.6, < 7.6.42023-07-07
CVE-2022-4361 [MEDIUM] CWE-81 CVE-2022-4361: Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) v
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServiceURL value or the redirect_uri.
nvd