VYPR

Keycloak

by Red Hat

Source repositories

CVEs (135)

  • CVE-2020-10734LowFeb 11, 2021
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable.

  • CVE-2014-3655MedNov 13, 2019
    risk 0.21cvss 4.3epss 0.00

    JBoss KeyCloak is vulnerable to soft token deletion via CSRF

  • CVE-2020-27826MedMay 28, 2021
    risk 0.20cvss 4.2epss 0.01

    A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API. This flaw allows an attacker to change its own NameID attribute to impersonate the admin user for any particular application.

  • CVE-2020-10686MedMay 4, 2020
    risk 0.20cvss 4.1epss 0.01

    A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.

  • CVE-2025-5416LowJun 20, 2025
    risk 0.18cvss 2.7epss 0.00

    A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

  • CVE-2020-1717LowFeb 11, 2021
    risk 0.18cvss 2.7epss 0.01

    A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack.

  • CVE-2019-3868LowApr 24, 2019
    risk 0.18cvss 3.8epss 0.01

    Keycloak up to version 6.0.0 allows the end user token (access or id token JWT) to be used as the session cookie for browser sessions for OIDC. As a result an attacker with access to service provider backend could hijack user’s browser session.

  • CVE-2024-1722LowFeb 29, 2024
    risk 0.17cvss 3.7epss 0.01

    A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

  • CVE-2016-8609LowAug 1, 2018
    risk 0.17cvss 3.7epss 0.02

    It was found that the keycloak before 2.3.0 did not implement authentication flow correctly. An attacker could use this flaw to construct a phishing URL, from which he could hijack the user's session. This could lead to information disclosure, or permit further possible attacks.

  • CVE-2025-12150LowFeb 27, 2026
    risk 0.13cvss 3.1epss 0.00

    A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the configured attestation policy and register untrusted or forged authenticators via submission of an attestation object with fmt: "none", even when the realm is…

  • CVE-2026-9088LowJun 5, 2026
    risk 0.11cvss 2.7epss 0.00

    A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured…

  • CVE-2020-10770MedDec 15, 2020
    risk 0.09cvss 5.3epss 0.70

    A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri. This flaw allows an attacker to use this parameter to execute a Server-side request forgery (SSRF) attack.

  • CVE-2026-9799MedJun 25, 2026
    risk 0.00cvss 4.6epss 0.00

    A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using a specific permission request prefix to bypass per-resource access control. This allows the user to gain…

  • CVE-2021-3513HigAug 22, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

  • CVE-2017-2582MedJul 26, 2018
    risk 0.00cvss 6.5epss 0.02

    It was found that while parsing the SAML messages the StaxParserUtil class of keycloak before 2.5.1 replaces special strings for obtaining attribute values with system property. This could allow an attacker to determine values of system properties at the attacked system by…

Page 7 of 7