CVE-2025-7784
- EPSS 0.01%
- Published 18.07.2025 13:48:45
- Last modified 11.08.2025 19:16:40
A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege e...
CVE-2025-3910
- EPSS 0.01%
- Published 29.04.2025 20:46:39
- Last modified 18.08.2025 15:55:00
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
CVE-2024-10234
- EPSS 0.42%
- Published 22.10.2024 14:15:14
- Last modified 23.07.2025 19:15:31
A vulnerability was found in Wildfly, where a user may perform Cross-site scripting in the Wildfly deployment system. This flaw allows an attacker or insider to execute a deployment with a malicious payload, which could trigger undesired behavior aga...
CVE-2024-3656
- EPSS 88.29%
- Published 09.10.2024 19:15:13
- Last modified 23.12.2024 14:15:05
A flaw was found in Keycloak. Certain endpoints in Keycloak's admin REST API allow low-privilege users to access administrative functionalities. This flaw allows users to perform actions reserved for administrators, potentially leading to data breach...
CVE-2024-8883
- EPSS 4.89%
- Published 19.09.2024 16:15:06
- Last modified 26.11.2024 19:15:32
A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is set to http://localhost or http://127.0.0.1, enabling sensitive information such as authorization codes...
CVE-2024-7260
- EPSS 0.15%
- Published 09.09.2024 19:15:14
- Last modified 01.10.2024 14:15:06
An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are made to trick a user to visit a malicious webpage. A trusted URL can trick users and automation into b...
CVE-2024-7318
- EPSS 0.34%
- Published 09.09.2024 19:15:14
- Last modified 07.10.2024 20:15:17
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additiona...
CVE-2024-7341
- EPSS 1.15%
- Published 09.09.2024 19:15:14
- Last modified 04.10.2024 12:48:43
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin option is configured. This flaw allows an attacker who ...
CVE-2024-4629
- EPSS 0.17%
- Published 03.09.2024 20:15:09
- Last modified 21.11.2024 09:43:14
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed...
CVE-2024-7885
- EPSS 6.4%
- Published 21.08.2024 14:15:09
- Last modified 25.09.2025 08:15:36
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection....