Show filters
57 Total Results
Displaying 21-30 of 57
Sort by:
Attacker Value
Unknown
CVE-2022-0084
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in XNIO, specifically in the notifyReadClosed method. The issue revealed this method was logging a message to another expected end. This flaw allows an attacker to send flawed requests to a server, possibly causing log contention-related performance concerns or an unwanted disk fill-up.
0
Attacker Value
Unknown
CVE-2021-3754
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
A flaw was found in keycloak where an attacker is able to register himself with the username same as the email ID of any existing user. This may cause trouble in getting password recovery email in case the user forgets the password.
0
Attacker Value
Unknown
CVE-2021-3632
Disclosure Date: August 26, 2022 (last updated November 29, 2024)
A flaw was found in Keycloak. This vulnerability allows anyone to register a new security device or key when there is not a device already registered for any user by using the WebAuthn password-less login flow.
0
Attacker Value
Unknown
CVE-2021-3827
Disclosure Date: August 23, 2022 (last updated October 08, 2023)
A flaw was found in keycloak, where the default ECP binding flow allows other authentication flows to be bypassed. By exploiting this behavior, an attacker can bypass the MFA authentication by sending a SOAP request with an AuthnRequest and Authorization header with the user's credentials. The highest threat from this vulnerability is to confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2022-2668
Disclosure Date: August 05, 2022 (last updated October 08, 2023)
An issue was discovered in Keycloak that allows arbitrary Javascript to be uploaded for the SAML protocol mapper even if the UPLOAD_SCRIPTS feature is disabled
0
Attacker Value
Unknown
CVE-2021-3461
Disclosure Date: April 01, 2022 (last updated October 07, 2023)
A flaw was found in keycloak where keycloak may fail to logout user session if the logout request comes from external SAML identity provider and Principal Type is set to Attribute [Name].
0
Attacker Value
Unknown
CVE-2022-0853
Disclosure Date: March 11, 2022 (last updated October 07, 2023)
A flaw was found in JBoss-client. The vulnerability occurs due to a memory leak on the JBoss client-side, when using UserTransaction repeatedly and leads to information leakage vulnerability.
0
Attacker Value
Unknown
CVE-2021-3637
Disclosure Date: July 09, 2021 (last updated November 28, 2024)
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
0
Attacker Value
Unknown
CVE-2021-20262
Disclosure Date: March 09, 2021 (last updated November 28, 2024)
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password. This flaw allows an attacker to take over an account if they can obtain temporary, physical access to a user’s browser. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
0
Attacker Value
Unknown
CVE-2020-27838
Disclosure Date: March 08, 2021 (last updated November 28, 2024)
A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients (like client secret) without authentication which could be an issue if the same PUBLIC client changed to CONFIDENTIAL later. The highest threat from this vulnerability is to data confidentiality.
0