CVE-2022-4039
- EPSS 0.79%
- Veröffentlicht 22.09.2023 15:15:09
- Zuletzt bearbeitet 21.11.2024 07:34:29
A flaw was found in Red Hat Single Sign-On for OpenShift container images, which are configured with an unsecured management interface enabled. This flaw allows an attacker to use this interface to deploy malicious code and access and modify potentia...
CVE-2022-3916
- EPSS 0.95%
- Veröffentlicht 20.09.2023 15:15:11
- Zuletzt bearbeitet 21.11.2024 07:20:31
A flaw was found in the offline_access scope in Keycloak. This issue would affect users of shared computers more (especially if cookies are not cleared), due to a lack of root session validation, and the reuse of session ids across root and user auth...
CVE-2023-1108
- EPSS 1.77%
- Veröffentlicht 14.09.2023 15:15:08
- Zuletzt bearbeitet 21.11.2024 07:38:28
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
- EPSS 1.27%
- Veröffentlicht 04.08.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:36:51
A flaw was found in Keycloaks OpenID Connect user authentication, which may incorrectly authenticate requests. An authenticated attacker who could obtain information from a user request within the same realm could use that data to impersonate the vic...
CVE-2022-4361
- EPSS 0.63%
- Veröffentlicht 07.07.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 07:35:08
Keycloak, an open-source identity and access management solution, has a cross-site scripting (XSS) vulnerability in the SAML or OIDC providers. The vulnerability can allow an attacker to execute malicious scripts by setting the AssertionConsumerServi...
CVE-2023-1664
- EPSS 0.43%
- Veröffentlicht 26.05.2023 18:15:09
- Zuletzt bearbeitet 15.01.2025 22:15:25
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certifi...
CVE-2022-1274
- EPSS 0.7%
- Veröffentlicht 29.03.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:40:23
A flaw was found in Keycloak in the execute-actions-email endpoint. This issue allows arbitrary HTML to be injected into emails sent to Keycloak users and can be misused to perform phishing or other attacks against users.
CVE-2022-2237
- EPSS 0.4%
- Veröffentlicht 27.03.2023 22:15:11
- Zuletzt bearbeitet 24.02.2025 20:15:31
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
CVE-2022-4492
- EPSS 0.6%
- Veröffentlicht 23.02.2023 20:15:12
- Zuletzt bearbeitet 12.03.2025 15:15:38
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol...
CVE-2022-1278
- EPSS 0.78%
- Veröffentlicht 13.09.2022 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:40:23
A flaw was found in WildFly, where an attacker can see deployment names, endpoints, and any other data the trace payload may contain.