Redhat

Keycloak

128 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Published 05.09.2025 20:06:14
  • Last modified 22.09.2025 16:15:39

A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of ...

  • EPSS 0.03%
  • Published 05.09.2025 19:59:04
  • Last modified 22.09.2025 16:15:39

A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description query parameter. This text is directly rendered in error pages without validation or sanitization. While HTML encoding prevents XS...

  • EPSS 0.05%
  • Published 21.08.2025 15:40:25
  • Last modified 22.09.2025 16:15:46

A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes placeholders within imported realm documents, potentially referencing environment variables. This substitution process allows for inj...

  • EPSS 0.07%
  • Published 06.08.2025 17:15:38
  • Last modified 04.09.2025 15:15:49

A vulnerability was found in Keycloak-services. Special characters used during e-mail registration may perform SMTP Injection and unexpectedly send short unwanted e-mails. The email is limited to 64 characters (limited local part of the email), so th...

  • EPSS 0.01%
  • Published 18.07.2025 13:48:45
  • Last modified 11.08.2025 19:16:40

A flaw was found in the Keycloak identity and access management system when Fine-Grained Admin Permissions(FGAPv2) are enabled. An administrative user with the manage-users role can escalate their privileges to realm-admin due to improper privilege e...

  • EPSS 0.01%
  • Published 10.07.2025 14:20:45
  • Last modified 21.08.2025 22:23:35

A flaw was found in Keycloak. When an authenticated attacker attempts to merge accounts with another existing account during an identity provider (IdP) login, the attacker will subsequently be prompted to "review profile" information. This vulnerabil...

  • EPSS 0.03%
  • Published 20.06.2025 16:04:05
  • Last modified 13.08.2025 13:44:11

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

  • EPSS 0.01%
  • Published 29.04.2025 20:46:39
  • Last modified 18.08.2025 15:55:00

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

  • EPSS 0.01%
  • Published 29.04.2025 20:45:29
  • Last modified 07.08.2025 13:15:36

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

  • EPSS 0.32%
  • Published 25.03.2025 08:20:57
  • Last modified 30.04.2025 03:15:17

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow ind...