Show filters
57 Total Results
Displaying 51-57 of 57
Sort by:
Attacker Value
Unknown
CVE-2019-9514
Disclosure Date: August 13, 2019 (last updated January 15, 2025)
Some HTTP/2 implementations are vulnerable to a reset flood, potentially leading to a denial of service. The attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer. Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both.
0
Attacker Value
Unknown
CVE-2019-10184
Disclosure Date: July 25, 2019 (last updated November 27, 2024)
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
0
Attacker Value
Unknown
CVE-2019-3872
Disclosure Date: June 12, 2019 (last updated November 27, 2024)
It was found that a SAMLRequest containing a script could be processed by Picketlink versions shipped in Jboss Application Platform 7.2.x and 7.1.x. An attacker could use this to send a malicious script to achieve cross-site scripting and obtain unauthorized information or conduct further attacks.
0
Attacker Value
Unknown
CVE-2019-3873
Disclosure Date: June 12, 2019 (last updated November 27, 2024)
It was found that Picketlink as shipped with Jboss Enterprise Application Platform 7.2 would accept an xinclude parameter in SAMLresponse XML. An attacker could use this flaw to send a URL to achieve cross-site scripting or possibly conduct further attacks.
0
Attacker Value
Unknown
CVE-2018-10934
Disclosure Date: March 27, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.
0
Attacker Value
Unknown
CVE-2017-12158
Disclosure Date: October 26, 2017 (last updated November 26, 2024)
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server.
0
Attacker Value
Unknown
CVE-2017-12159
Disclosure Date: October 26, 2017 (last updated November 26, 2024)
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
0