Vulnerabilities > Keycloak > Keycloak

DATE CVE VULNERABILITY TITLE RISK
2018-07-23 CVE-2018-10912 Infinite Loop vulnerability in multiple products
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement.
network
low complexity
keycloak redhat CWE-835
4.0
2018-02-21 CVE-2017-12161 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Keycloak
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request.
network
keycloak CWE-640
4.3
2017-12-29 CVE-2014-3651 Resource Exhaustion vulnerability in Keycloak
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.
network
low complexity
keycloak CWE-400
5.0
2017-10-26 CVE-2017-12159 Insufficient Session Expiration vulnerability in multiple products
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session.
network
low complexity
redhat keycloak CWE-613
5.0
2017-10-26 CVE-2017-12158 Cross-site Scripting vulnerability in multiple products
It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations.
3.5
2017-10-18 CVE-2014-3709 Cross-Site Request Forgery (CSRF) vulnerability in Keycloak
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
network
keycloak CWE-352
6.8