CVE-2024-7885
- EPSS 2.64%
- Veröffentlicht 21.08.2024 14:15:09
- Zuletzt bearbeitet 24.09.2026 04:17:34
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection....
CVE-2023-6787
- EPSS 0.74%
- Veröffentlicht 25.04.2024 16:15:10
- Zuletzt bearbeitet 30.06.2025 13:49:15
A flaw was found in Keycloak that occurs from an error in the re-authentication mechanism within org.keycloak.authentication. This flaw allows hijacking an active Keycloak session by triggering a new authentication process with the query parameter "p...
CVE-2024-1132
- EPSS 1.55%
- Veröffentlicht 17.04.2024 14:15:07
- Zuletzt bearbeitet 04.08.2026 18:16:40
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain ...