Show filters
175 Total Results
Displaying 121-130 of 175
Sort by:
Attacker Value
Unknown

CVE-2020-1727

Disclosure Date: June 22, 2020 (last updated February 21, 2025)
A vulnerability was found in Keycloak before 9.0.2, where every Authorization URL that points to an IDP server lacks proper input validation as it allows a wide range of characters. This flaw allows a malicious to craft deep links that introduce further attack scenarios on affected clients.
Attacker Value
Unknown

CVE-2020-1758

Disclosure Date: May 15, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak in versions before 10.0.0, where it does not perform the TLS hostname verification while sending emails using the SMTP server. This flaw allows an attacker to perform a man-in-the-middle (MITM) attack.
Attacker Value
Unknown

CVE-2020-1714

Disclosure Date: May 13, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak before version 11.0.0, where the code base contains usages of ObjectInputStream without type checks. This flaw allows an attacker to inject arbitrarily serialized Java Objects, which would then get deserialized in a privileged context and potentially lead to remote code execution.
Attacker Value
Unknown

CVE-2020-1718

Disclosure Date: May 12, 2020 (last updated February 21, 2025)
A flaw was found in the reset credential flow in all Keycloak versions before 8.0.0. This flaw allows an attacker to gain unauthorized access to the application.
Attacker Value
Unknown

CVE-2020-1724

Disclosure Date: May 11, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak in versions before 9.0.2. This flaw allows a malicious user that is currently logged in, to see the personal information of a previously logged out user in the account manager section.
Attacker Value
Unknown

CVE-2020-1698

Disclosure Date: May 11, 2020 (last updated February 21, 2025)
A flaw was found in keycloak in versions before 9.0.0. A logged exception in the HttpMethod class may leak the password given as parameter. The highest threat from this vulnerability is to data confidentiality.
Attacker Value
Unknown

CVE-2019-10169

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak’s user-managed access interface, where it would permit a script to be set in the UMA policy. This flaw allows an authenticated attacker with UMA permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the user running application.
Attacker Value
Unknown

CVE-2019-10170

Disclosure Date: May 08, 2020 (last updated February 21, 2025)
A flaw was found in the Keycloak admin console, where the realm management interface permits a script to be set via the policy. This flaw allows an attacker with authenticated user and realm management permissions to configure a malicious script to trigger and execute arbitrary code with the permissions of the application user.
Attacker Value
Unknown

CVE-2020-10686

Disclosure Date: May 04, 2020 (last updated February 21, 2025)
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself. The attacker could then use the remove devices form to post different credential IDs and possibly remove MFA devices for other users.
Attacker Value
Unknown

CVE-2020-10512

Disclosure Date: April 15, 2020 (last updated February 21, 2025)
HGiga C&Cmail CCMAILQ before olln-calendar-6.0-100.i386.rpm and CCMAILN before olln-calendar-5.0-100.i386.rpm contains a SQL Injection vulnerability which allows attackers to injecting SQL commands in the URL parameter to execute unauthorized commands.