VYPR

Single Sign On

by Red Hat

CVEs (121)

  • CVE-2025-9784HigSep 2, 2025
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in Undertow where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing…

  • CVE-2024-7885HigAug 21, 2024
    risk 0.42cvss 7.5epss 0.03

    A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different…

  • CVE-2024-1635HigFeb 19, 2024
    risk 0.42cvss 7.5epss 0.05

    A vulnerability was found in Undertow. This vulnerability impacts a server that supports the wildfly-http-client protocol. Whenever a malicious user opens and closes a connection with the HTTP port of the server and then closes the connection immediately, the server will end…

  • CVE-2022-4244HigSep 25, 2023
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in codeplex-codehaus. A directory traversal attack (also known as path traversal) aims to access files and directories stored outside the intended folder. By manipulating files with "dot-dot-slash (../)" sequences and their variations or by using absolute file…

  • CVE-2022-1438MedSep 20, 2023
    risk 0.42cvss 6.4epss 0.01

    A flaw was found in Keycloak. Under specific circumstances, HTML entities are not sanitized during user impersonation, resulting in a Cross-site scripting (XSS) vulnerability.

  • CVE-2023-1108HigSep 14, 2023
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

  • CVE-2023-1664MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated…

  • CVE-2022-4492HigFeb 23, 2023
    risk 0.42cvss 7.5epss 0.01

    The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol.

  • CVE-2022-0084HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or…

  • CVE-2021-3859HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

  • CVE-2021-3632HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.

  • CVE-2021-3690HigAug 23, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

  • CVE-2022-1466MedApr 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

  • CVE-2020-14299MedOct 16, 2020
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in JBoss EAP, where the authentication configuration is set-up using a legacy SecurityRealm, to delegate to a legacy PicketBox SecurityDomain, and then reloaded to admin-only mode. This flaw allows an attacker to perform a complete authentication bypass by using…

  • CVE-2020-25644HigOct 6, 2020
    risk 0.42cvss 7.5epss 0.02

    A memory leak flaw was found in WildFly OpenSSL in versions prior to 1.1.3.Final, where it removes an HTTP session. It may allow the attacker to cause OOM leading to a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2020-10758HigSep 16, 2020
    risk 0.42cvss 7.5epss 0.02

    A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

  • CVE-2020-14307MedJul 24, 2020
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in Wildfly's Enterprise Java Beans (EJB) versions shipped with Red Hat JBoss EAP 7, where SessionOpenInvocations are never removed from the remote InvocationTracker after a response is received in the EJB Client, as well as the server. This flaw allows…

  • CVE-2020-10719MedMay 26, 2020
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

  • CVE-2019-10184HigJul 25, 2019
    risk 0.42cvss 7.5epss 0.03

    undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

  • CVE-2019-3875MedJun 12, 2019
    risk 0.42cvss 6.5epss 0.00

    A vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRL, where the CRL list can be obtained from the URL provided in the certificate itself (CDP) or through the separately configured path. The…

Page 3 of 7