CVE-2022-3916
- EPSS 0.23%
- Veröffentlicht 20.09.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:31
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user auth...
CVE-2023-4853
- EPSS 0.46%
- Veröffentlicht 20.09.2023 10:15:14
- Zuletzt bearbeitet 21.11.2024 08:36:06
A flaw was found in Quarkus where HTTP security policies are not sanitizing certain character permutations correctly when accepting requests, resulting in incorrect evaluation of permissions. This issue could allow an attacker to bypass the security ...
CVE-2022-3466
- EPSS 0.02%
- Veröffentlicht 15.09.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:19:35
The version of cri-o as released for Red Hat OpenShift Container Platform 4.9.48, 4.10.31, and 4.11.6 via RHBA-2022:6316, RHBA-2022:6257, and RHBA-2022:6658, respectively, included an incorrect version of cri-o missing the fix for CVE-2022-27652, whi...
CVE-2023-1108
- EPSS 0.57%
- Veröffentlicht 14.09.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:28
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
- EPSS 3.94%
- Veröffentlicht 04.08.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:36:51
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the vic...
CVE-2022-4361
- EPSS 1.43%
- Veröffentlicht 07.07.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:35:08
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServi...
CVE-2023-3089
- EPSS 0.05%
- Veröffentlicht 05.07.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:25
A compliance problem was found in the Red Hat OpenShift Container Platform. Red Hat discovered that, when FIPS mode was enabled, not all of the cryptographic modules in use were FIPS-validated.
CVE-2023-2253
- EPSS 0.14%
- Veröffentlicht 06.06.2023 20:15:12
- Zuletzt bearbeitet 07.01.2025 22:15:29
A flaw was found in the `/v2/_catalog` endpoint in distribution/distribution, which accepts a parameter to control the maximum number of records returned (query string: `n`). This vulnerability allows a malicious user to submit an unreasonably large ...
CVE-2023-1668
- EPSS 0.32%
- Veröffentlicht 10.04.2023 22:15:09
- Zuletzt bearbeitet 23.04.2025 17:16:28
A flaw was found in openvswitch (OVS). When processing an IP packet with protocol 0, OVS will install the datapath flow without the action modifying the IP header. This issue results (for both kernel and userspace datapath) in installing a datapath f...
CVE-2022-1274
- EPSS 0.86%
- Veröffentlicht 29.03.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:23
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.