Vulnerabilities > Redhat > Keycloak > 6.0.2

DATE CVE VULNERABILITY TITLE RISK
2020-02-10 CVE-2020-1697 Cross-site Scripting vulnerability in Redhat Keycloak
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks.
network
low complexity
redhat CWE-79
5.4
2020-01-08 CVE-2019-14820 Unspecified vulnerability in Redhat products
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL.
network
low complexity
redhat
4.3
2020-01-07 CVE-2019-14837 Use of Hard-coded Credentials vulnerability in Redhat Keycloak
A flaw was found in keycloack before version 8.0.0.
network
low complexity
redhat CWE-798
critical
9.1
2019-10-15 CVE-2019-14832 Incorrect Authorization vulnerability in Redhat Keycloak
A flaw was found in the Keycloak REST API before version 8.0.0 where it would permit user access from a realm the user was not configured.
network
high complexity
redhat CWE-863
7.5