CVE-2021-3424
- EPSS 0.77%
- Veröffentlicht 01.06.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 06:21:28
A flaw was found in keycloak as shipped in Red Hat Single Sign-On 7.4 where IDN homograph attacks are possible. A malicious user can register himself with a name already registered and trick admin to grant him extra privileges.
CVE-2020-27826
- EPSS 0.57%
- Veröffentlicht 28.05.2021 11:15:07
- Zuletzt bearbeitet 21.11.2024 05:21:53
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular ...
CVE-2020-10695
- EPSS 0.25%
- Veröffentlicht 26.05.2021 22:15:07
- Zuletzt bearbeitet 21.11.2024 04:55:52
An insecure modification flaw in the /etc/passwd file was found in the redhat-sso-7 container. An attacker with access to the container can use this flaw to modify the /etc/passwd and escalate their privileges.
CVE-2021-20262
- EPSS 0.33%
- Veröffentlicht 09.03.2021 18:15:15
- Zuletzt bearbeitet 21.11.2024 05:46:14
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from th...
CVE-2020-27838
- EPSS 17.94%
- Veröffentlicht 08.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:21:54
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFI...
- EPSS 0.77%
- Veröffentlicht 11.02.2021 18:15:14
- Zuletzt bearbeitet 21.11.2024 05:11:13
A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.
CVE-2020-10734
- EPSS 0.21%
- Veröffentlicht 11.02.2021 18:15:13
- Zuletzt bearbeitet 21.11.2024 04:55:57
A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.
- EPSS 0.95%
- Veröffentlicht 12.01.2021 15:15:13
- Zuletzt bearbeitet 21.11.2024 05:03:02
The "Test Connection" available in v7.x of the Red Hat Single Sign On application console can permit an authorized user to cause SMTP connections to be attempted to arbitrary hosts and ports of the user's choosing, and originating from the RHSSO inst...
CVE-2020-25689
- EPSS 1.5%
- Veröffentlicht 02.11.2020 21:15:27
- Zuletzt bearbeitet 21.11.2024 05:18:28
A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows ...
CVE-2020-14299
- EPSS 1.38%
- Veröffentlicht 16.10.2020 14:15:11
- Zuletzt bearbeitet 21.11.2024 05:02:57
A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete a...