Redhat Single Sign-On vulnerabilities
98 known vulnerabilities affecting redhat/single_sign-on.
Total CVEs
98
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
4
Severity breakdown
CRITICAL10HIGH43MEDIUM40LOW5
Vulnerabilities
Page 5 of 5
CVE-2022-2237P4MEDIUMCVSS 6.1v7.02023-03-27
CVE-2022-2237 [MEDIUM] CWE-601 CVE-2022-2237: A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Op
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
nvd
CVE-2019-14838P4MEDIUMCVSS 4.9v7.3.52019-10-14
CVE-2019-14838 [MEDIUM] CWE-284 CVE-2019-14838: A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Dep
A flaw was found in wildfly-core before 7.2.5.GA. The Management users with Monitor, Auditor and Deployer Roles should not be allowed to modify the runtime state of the server
nvd
CVE-2018-10934P4MEDIUMCVSS 5.4v7.22019-03-27
CVE-2018-10934 [MEDIUM] CWE-79 CVE-2018-10934: A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
nvd
CVE-2020-1697P4MEDIUMCVSS 5.4v7.32020-02-10
CVE-2020-1697 [MEDIUM] CWE-79 CVE-2020-1697: It was found in all keycloak versions before 9.0.0 that links to external applications (Application
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks. An authed malicious user could create URLs to trick users in other realms, and possibly conduct further attacks.
nvd
CVE-2019-3872P4MEDIUMCVSS 5.4v7.02019-06-12
CVE-2019-3872 [MEDIUM] CWE-79 CVE-2019-3872: It was found that a SAMLRequest containing a script could be processed by Picketlink versions shippe
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
nvd
CVE-2019-3875P4MEDIUMCVSS 4.8v7.32019-06-12
CVE-2019-3875 [MEDIUM] CWE-295 CVE-2019-3875: A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verificatio
A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The CRL are often available over the network through unsecured protocols ('http
nvd
CVE-2020-1724P4MEDIUMCVSS 4.3v7.02020-05-11
CVE-2020-1724 [MEDIUM] CWE-613 CVE-2020-1724: A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is cur
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
nvd
CVE-2019-14820P4MEDIUMCVSS 4.3v7.32020-01-08
CVE-2019-14820 [MEDIUM] CWE-200 CVE-2019-14820: It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.c
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
nvd
CVE-2020-27826P4MEDIUMCVSS 4.2v7.4v7.4.42021-05-28
CVE-2020-27826 [MEDIUM] CWE-250 CVE-2020-27826: A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadat
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.
nvd
CVE-2019-10157P4MEDIUMCVSS 5.5fixed in 7.3.22019-06-12
CVE-2019-10157 [MEDIUM] CWE-345 CVE-2019-10157: It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web to
It was found that Keycloak's Node.js adapter before version 4.8.3 did not properly verify the web token received from the server in its backchannel logout . An attacker with local access could use this to construct a malicious web token setting an NBF parameter that could prevent user access indefinitely.
nvd
CVE-2018-10912P4MEDIUMCVSS 4.9v7.22018-07-23
CVE-2018-10912 [MEDIUM] CWE-835 CVE-2018-10912: keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycl
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
nvd
CVE-2022-2764P4MEDIUMCVSS 4.9v7.02022-09-01
CVE-2022-2764 [MEDIUM] CWE-400 CVE-2022-2764: A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAS
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
nvd
CVE-2019-14885P4MEDIUMCVSS 4.3v7.02020-01-23
CVE-2019-14885 [MEDIUM] CWE-532 CVE-2019-14885: A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential informa
A flaw was found in the JBoss EAP Vault system in all versions before 7.2.6.GA. Confidential information of the system property's security attribute value is revealed in the JBoss EAP log file when executing a JBoss CLI 'reload' command. This flaw can lead to the exposure of confidential information.
nvd
CVE-2022-2256P4LOWCVSS 3.8v7.02022-09-01
CVE-2022-2256 [LOW] CWE-79 CVE-2022-2256: A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single
A Stored Cross-site scripting (XSS) vulnerability was found in keycloak as shipped in Red Hat Single Sign-On 7. This flaw allows a privileged attacker to execute malicious scripts in the admin console, abusing the default roles functionality.
nvd
CVE-2026-4874P4LOWCVSS 3.1v7.02026-03-26
CVE-2026-4874 [LOW] CWE-918 CVE-2026-4874: A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSR
A flaw was found in Keycloak. An authenticated attacker can perform Server-Side Request Forgery (SSRF) by manipulating the `client_session_host` parameter during refresh token requests. This occurs when a Keycloak client is configured to use the `backchannel.logout.url` with the `application.session.host` placeholder. Successful exploitation allows the a
nvd
CVE-2020-14341P4LOWCVSS 2.7≥ 7.0, ≤ 7.42021-01-12
CVE-2020-14341 [LOW] CWE-385 CVE-2020-14341: The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO installation. By observing differences in the timings of these scans, an attacker may glean information abou
nvd
CVE-2020-1717P4LOWCVSS 2.7v7.02021-02-11
CVE-2020-1717 [LOW] CWE-209 CVE-2020-1717: A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
nvd
CVE-2020-10734P4LOWCVSS 3.3v7.02021-02-11
CVE-2020-10734 [LOW] CWE-352 CVE-2020-10734: A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF pr
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
nvd
← Previous5 / 5