Redhat

Data Grid

45 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.31%
  • Veröffentlicht 18.08.2026 20:40:17
  • Zuletzt bearbeitet 20.08.2026 15:17:28

A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. The mechanism used to protect the account-linking process from unauthorized requests relies on a ...

  • EPSS 0.25%
  • Veröffentlicht 05.08.2026 13:50:50
  • Zuletzt bearbeitet 20.08.2026 11:16:20

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy fails to properly validate the claim path for User Property mappers, allowing them to write values to ...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2026 13:50:03
  • Zuletzt bearbeitet 20.08.2026 11:16:20

A flaw was found in Keycloak's Authorization Services. The component responsible for matching request paths to security policies (PathMatcher) does not properly normalize URIs before comparison. By adding extra characters like a trailing slash or mat...

  • EPSS 0.15%
  • Veröffentlicht 05.08.2026 13:44:09
  • Zuletzt bearbeitet 10.08.2026 18:52:14

A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red Hat Build of Keycloak. When importing identity provider metadata that lacks specific usage attribute...

  • EPSS 0.18%
  • Veröffentlicht 02.08.2026 05:18:58
  • Zuletzt bearbeitet 07.08.2026 18:24:33

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing access during business hours). A flaw was discovered where a user can include a fake time value in t...

  • EPSS 0.14%
  • Veröffentlicht 02.08.2026 05:18:42
  • Zuletzt bearbeitet 07.08.2026 18:35:30

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcing security policies during client registration and configuration in Red Hat Build of Keycloak. The is...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 07:08:31
  • Zuletzt bearbeitet 07.08.2026 14:35:42

A flaw was found in the keycloak-services component of Keycloak, which handles OpenID Connect (OIDC) authentication flows. The issue occurs because the security check designed to prevent HTTP parameter pollution only inspects the query portion of a r...

  • EPSS 0.18%
  • Veröffentlicht 31.07.2026 07:08:24
  • Zuletzt bearbeitet 07.08.2026 14:30:12

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security requirements on client configurations, such as requiring encrypted connections for redirect URIs. Du...

  • EPSS 0.2%
  • Veröffentlicht 31.07.2026 07:08:20
  • Zuletzt bearbeitet 07.08.2026 14:47:32

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access management solution used to secure modern applications and services. The issue occurs when a confidential cli...

  • EPSS 0.19%
  • Veröffentlicht 31.07.2026 07:03:36
  • Zuletzt bearbeitet 07.08.2026 14:59:14

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoints in the admin REST API do not properly enforce authorization checks when managing composite roles. This allows a delegated admin...