CVE-2021-3629
- EPSS 0.29%
- Veröffentlicht 24.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:01
A flaw was found in Undertow. A potential security issue in flow control handling by the browser over http/2 may potentially cause overhead or a denial of service in the server. The highest threat from this vulnerability is availability. This flaw af...
CVE-2021-3717
- EPSS 0.04%
- Veröffentlicht 24.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:14
A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_USER access to all users on the machine. The highest threat from this vulnerability is to confidentiality, inte...
CVE-2022-1466
- EPSS 0.16%
- Veröffentlicht 26.04.2022 19:15:49
- Zuletzt bearbeitet 21.11.2024 06:40:46
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
CVE-2021-3461
- EPSS 0.05%
- Veröffentlicht 01.04.2022 23:15:10
- Zuletzt bearbeitet 21.11.2024 06:21:35
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
CVE-2022-0853
- EPSS 1.31%
- Veröffentlicht 11.03.2022 18:15:25
- Zuletzt bearbeitet 21.11.2024 06:39:31
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
CVE-2021-4104
- EPSS 69.28%
- Veröffentlicht 14.12.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 06:36:54
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...
CVE-2021-3637
- EPSS 0.47%
- Veröffentlicht 09.07.2021 11:15:09
- Zuletzt bearbeitet 21.11.2024 06:22:02
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
CVE-2021-3424
- EPSS 0.16%
- Veröffentlicht 01.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:28
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
CVE-2020-27826
- EPSS 0.17%
- Veröffentlicht 28.05.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:53
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular ...
CVE-2020-10695
- EPSS 0.04%
- Veröffentlicht 26.05.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:52
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.