Vulnerabilities > Redhat > Keycloak > 8.0.2

DATE CVE VULNERABILITY TITLE RISK
2020-05-11 CVE-2020-1698 Information Exposure Through Log Files vulnerability in Redhat Keycloak
A flaw was found in keycloak in versions before 9.0.0.
local
low complexity
redhat CWE-532
5.5
2020-05-04 CVE-2020-10686 Unspecified vulnerability in Redhat Keycloak 8.0.2/9.0.0
A flaw was found in Keycloak version 8.0.2 and 9.0.0, and was fixed in Keycloak version 9.0.1, where a malicious user registers as oneself.
network
low complexity
redhat
4.7
2020-04-06 CVE-2020-1728 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
A vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing general HTTP security headers in HTTP-responses.
network
low complexity
redhat quarkus CWE-1021
5.4
2020-03-24 CVE-2020-1744 Improper Handling of Exceptional Conditions vulnerability in Redhat Keycloak
A flaw was found in keycloak before version 9.0.1.
network
high complexity
redhat CWE-755
5.6
2020-02-10 CVE-2020-1697 Cross-site Scripting vulnerability in Redhat Keycloak
It was found in all keycloak versions before 9.0.0 that links to external applications (Application Links) in the admin console are not validated properly and could allow Stored XSS attacks.
network
low complexity
redhat CWE-79
5.4