Launch Week Day 1: Announcing Security Design Review
maven

org.keycloak:keycloak-core

View on maven registry
58 Total advisories
58 Vulnerabilities
0 Malware

Vulnerabilities

HIGH 8.8
Maven

CVE-2023-4918

Keycloak vulnerable to Plaintext Storage of User Password

UNKNOWN
Maven

GHSA-755v-r4x4-qf7m

Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown

MEDIUM 5.4
Maven

CVE-2022-0225

Keycloak XSS via use of malicious payload as group name when creating new group from admin console

HIGH 7.1
Maven

CVE-2024-10039

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

MEDIUM 4.6
Maven

CVE-2023-6927

keycloak-core: open redirect via "form_post.jwt" JARM response mode

MEDIUM 4.4
Maven

CVE-2024-7260

Keycloak Open Redirect vulnerability

MEDIUM 6.5
Maven

CVE-2023-6841

Keycloak Denial of Service vulnerability

MEDIUM 4.8
Maven

CVE-2024-7318

Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity

LOW 3.8
Maven

CVE-2024-4028

Keycloak allows cross-site scripting (XSS)

MEDIUM 5.4
Maven

CVE-2020-35509

Keycloak vulnerable to Improper Certificate Validation

MEDIUM 4.8
Maven

GHSA-57rh-gr4v-j5f6

Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date

LOW 3.7
Maven

GHSA-3hrr-xwvg-hxvr

Duplicate Advisory: Keycloak DoS via account lockout

MEDIUM 5.3
Maven

GHSA-j9xq-j329-2xvg

Duplicate Advisory: Keycloak user may register themselves with same email ID of any existing user

MEDIUM 6.5
Maven

GHSA-vhvq-jh34-3fc8

Duplicate Advisory: Keycloak allows impersonation and lockout due to email trust not being handled correctly

MEDIUM 6.5
Maven

GHSA-c892-cwq6-qrqf

Duplicate Advisory: Keycloak vulnerable to untrusted certificate validation

UNKNOWN
Maven

GHSA-qgm9-232x-hwpx

Moderate severity vulnerability that affects org.keycloak:keycloak-core

MEDIUM 5.4
Maven

GHSA-w8v7-c7pm-7wfr

Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)

UNKNOWN
Maven

CVE-2017-12161

Moderate severity vulnerability that affects org.keycloak:keycloak-core

UNKNOWN
Maven

CVE-2020-1728

Improper Restriction of Rendered UI Layers or Frames in Keycloak

UNKNOWN
Maven

CVE-2016-8629

Moderate severity vulnerability that affects org.keycloak:keycloak-core

LOW 2.7
Maven

GHSA-gmrm-8fx4-66x7

Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials

MEDIUM 4.3
Maven

CVE-2020-1724

Keycloak Insufficient Session Expiry

MEDIUM 4.7
Maven

CVE-2020-10686

Keycloak users may be able to remove MFA from other users' devices

MEDIUM 6.5
Maven

CVE-2020-27838

Keycloak discloses information without authentication

MEDIUM 5.5
Maven

CVE-2020-1698

Keycloak leaks sensitive information in logged exceptions

MEDIUM 6.5
Maven

CVE-2023-0105

Keycloak: Impersonation and lockout possible through incorrect handling of email trust

MEDIUM 6.8
Maven

CVE-2021-20262

Keycloak Missing authentication for critical function

MEDIUM 6.5
Maven

CVE-2023-1664

Keycloak Untrusted Certificate Validation vulnerability

MEDIUM 6.1
Maven

CVE-2014-3656

JBoss KeyCloak Cross-site Scripting Vulnerability

HIGH 8.8
Maven

CVE-2020-1714

Improper Input Validation in Keycloak

MEDIUM 6.1
Maven

CVE-2018-14658

Keycloak Open Redirect

MEDIUM 4.3
Maven

CVE-2021-3856

Keycloak has Files or Directories Accessible to External Parties

CRITICAL 9.1
Maven

CVE-2019-14837

keycloak vulnerable to unauthorized login via mail server setup

MEDIUM 5.9
Maven

CVE-2017-2585

keycloak-core vulnerable to timing attacks against JWS token verification

MEDIUM 6.5
Maven

CVE-2017-2582

keycloak-core discloses system properties

MEDIUM 6.5
Maven

CVE-2023-0091

Keycloak has lack of validation of access token on client registrations endpoint

MEDIUM 6.5
Maven

CVE-2022-1466

Improper authorization in Keycloak

HIGH 7.5
Maven

CVE-2021-3632

Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow

MEDIUM 6.1
Maven

CVE-2021-20323

Cross-site Scripting in Keycloak

HIGH 7.3
Maven

CVE-2021-20202

Temporary Directory Hijacking Vulnerability in Keycloak

CRITICAL 9.6
Maven

CVE-2021-20195

keycloak Self Stored Cross-site Scripting vulnerability

HIGH 8.8
Maven

CVE-2020-27826

Authentication Bypass in keycloak

MEDIUM 5.6
Maven

CVE-2020-1744

Exposure of Sensitive Information in keycloak

CRITICAL 9.8
Maven

CVE-2020-1731

Predictable password in Keycloak

MEDIUM 5.4
Maven

CVE-2020-1697

XSS in Keycloak

HIGH 8.1
Maven

CVE-2020-14389

Improper privilege management in Keycloak

MEDIUM 5.3
Maven

CVE-2020-10770

Keycloak vulnerable to Server-Side Request Forgery

MEDIUM 4.8
Maven

CVE-2019-3875

Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak

LOW 3.8
Maven

CVE-2019-3868

Exposure of Sensitive Information to an Unauthorized Actor in Keycloak

MEDIUM 4.3
Maven

CVE-2019-14820

Exposure of Sensitive Information to an Unauthorized Actor in Keycloak

HIGH 8.1
Maven

CVE-2019-10201

Improper Verification of Cryptographic Signature in keycloak

HIGH 8.8
Maven

CVE-2019-10199

Improper Input Validation and Cross-Site Request Forgery in Keycloak

HIGH 7.2
Maven

CVE-2019-10170

Privilege Defined With Unsafe Actions in Keycloak

HIGH 8.1
Maven

CVE-2018-14637

Improper Authentication in Keycloak

MEDIUM 4.9
Maven

CVE-2018-10912

Moderate severity vulnerability that affects org.keycloak:keycloak-core

HIGH 7.5
Maven

CVE-2017-2646

Keycloak vulnerable to infinite loop based Denial of Service

HIGH 8.1
Maven

CVE-2016-8609

Improper Authentication in org.keycloak:keycloak-core

HIGH 7.5
Maven

CVE-2014-3651

Keycloak vulnerable to uncontrolled resource consumption

Ready to move

Start Securing

Free, no credit card | First findings in minutes