Dependency scanning
Check whether org.keycloak:keycloak-core is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2024-10039
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
CVE-2024-7318
Keycloaks's One Time Passcode (OTP) is valid longer than expiration timeSeverity
CVE-2023-6841
Keycloak Denial of Service vulnerability
CVE-2024-7260
Keycloak Open Redirect vulnerability
GHSA-gmrm-8fx4-66x7
Duplicate Advisory: Keycloak: Leak of configured LDAP bind credentials
CVE-2023-6927
keycloak-core: open redirect via "form_post.jwt" JARM response mode
CVE-2024-4028
Keycloak allows cross-site scripting (XSS)
CVE-2017-1000500
Moderate severity vulnerability that affects org.keycloak:keycloak-core
CVE-2022-0225
Stored Cross-Site Scripting (XSS) in Keycloak via groups dropdown
CVE-2023-4918
Keycloak vulnerable to Plaintext Storage of User Password
CVE-2022-0225
Keycloak XSS via use of malicious payload as group name when creating new group from admin console
CVE-2020-35509
Keycloak vulnerable to Improper Certificate Validation
GHSA-57rh-gr4v-j5f6
Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date
GHSA-3hrr-xwvg-hxvr
Duplicate Advisory: Keycloak DoS via account lockout
GHSA-j9xq-j329-2xvg
Duplicate Advisory: Keycloak user may register themselves with same email ID of any existing user
GHSA-vhvq-jh34-3fc8
Duplicate Advisory: Keycloak allows impersonation and lockout due to email trust not being handled correctly
GHSA-c892-cwq6-qrqf
Duplicate Advisory: Keycloak vulnerable to untrusted certificate validation
GHSA-w8v7-c7pm-7wfr
Duplicate Advisory: Keycloak vulnerable to Cross-Site Scripting (XSS)
CVE-2017-12161
Moderate severity vulnerability that affects org.keycloak:keycloak-core
CVE-2020-1728
Improper Restriction of Rendered UI Layers or Frames in Keycloak
CVE-2016-8629
Moderate severity vulnerability that affects org.keycloak:keycloak-core
CVE-2020-1724
Keycloak Insufficient Session Expiry
CVE-2020-10686
Keycloak users may be able to remove MFA from other users' devices
CVE-2020-27838
Keycloak discloses information without authentication
CVE-2020-1698
Keycloak leaks sensitive information in logged exceptions
CVE-2023-0105
Keycloak: Impersonation and lockout possible through incorrect handling of email trust
CVE-2021-20262
Keycloak Missing authentication for critical function
CVE-2023-1664
Keycloak Untrusted Certificate Validation vulnerability
CVE-2014-3656
JBoss KeyCloak Cross-site Scripting Vulnerability
CVE-2020-1714
Improper Input Validation in Keycloak
CVE-2018-14658
Keycloak Open Redirect
CVE-2021-3856
Keycloak has Files or Directories Accessible to External Parties
CVE-2019-14837
keycloak vulnerable to unauthorized login via mail server setup
CVE-2017-2585
keycloak-core vulnerable to timing attacks against JWS token verification
CVE-2017-2582
keycloak-core discloses system properties
CVE-2023-0091
Keycloak has lack of validation of access token on client registrations endpoint
CVE-2022-1466
Improper authorization in Keycloak
CVE-2021-3632
Keycloak allows anyone to register new security device or key for any user by using WebAuthn password-less login flow
CVE-2021-20323
Cross-site Scripting in Keycloak
CVE-2021-20202
Temporary Directory Hijacking Vulnerability in Keycloak
CVE-2021-20195
keycloak Self Stored Cross-site Scripting vulnerability
CVE-2020-27826
Authentication Bypass in keycloak
CVE-2020-1744
Exposure of Sensitive Information in keycloak
CVE-2020-1731
Predictable password in Keycloak
CVE-2020-1697
XSS in Keycloak
CVE-2020-14389
Improper privilege management in Keycloak
CVE-2020-10770
Keycloak vulnerable to Server-Side Request Forgery
CVE-2019-3875
Improper Certificate Validation and Insufficient Verification of Data Authenticity in Keycloak
CVE-2019-3868
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
CVE-2019-14820
Exposure of Sensitive Information to an Unauthorized Actor in Keycloak
CVE-2019-10201
Improper Verification of Cryptographic Signature in keycloak
CVE-2019-10199
Improper Input Validation and Cross-Site Request Forgery in Keycloak
CVE-2019-10170
Privilege Defined With Unsafe Actions in Keycloak
CVE-2018-14637
Improper Authentication in Keycloak
CVE-2018-10912
Moderate severity vulnerability that affects org.keycloak:keycloak-core
CVE-2017-2646
Keycloak vulnerable to infinite loop based Denial of Service
CVE-2016-8609
Improper Authentication in org.keycloak:keycloak-core
CVE-2014-3651
Keycloak vulnerable to uncontrolled resource consumption
Browse more Maven advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes