Vulnerabilities > Redhat > Keycloak > Medium

DATE CVE VULNERABILITY TITLE RISK
2021-05-28 CVE-2020-27826 Execution with Unnecessary Privileges vulnerability in Redhat Keycloak
A flaw was found in Keycloak before version 12.0.0 where it is possible to update the user's metadata attributes using Account REST API.
network
redhat CWE-250
4.9
2021-05-28 CVE-2021-20195 Improper Encoding or Escaping of Output vulnerability in Redhat Keycloak
A flaw was found in keycloak in versions before 13.0.0.
network
redhat CWE-116
6.8
2021-05-12 CVE-2021-20202 Insecure Temporary File vulnerability in Redhat Keycloak
A flaw was found in keycloak.
local
low complexity
redhat CWE-377
4.6
2021-03-09 CVE-2021-20262 Missing Authentication for Critical Function vulnerability in Redhat Keycloak and Single Sign-On
A flaw was found in Keycloak 12.0.0 where re-authentication does not occur while updating the password.
local
low complexity
redhat CWE-306
4.6
2021-03-08 CVE-2020-27838 Improper Authentication vulnerability in Redhat Keycloak
A flaw was found in keycloak in versions prior to 13.0.0.
network
redhat CWE-287
4.3
2021-02-11 CVE-2020-1717 Information Exposure Through an Error Message vulnerability in Redhat products
A flaw was found in Keycloak 7.0.1.
network
low complexity
redhat CWE-209
4.0
2021-01-28 CVE-2020-1725 Incorrect Authorization vulnerability in Redhat Keycloak
A flaw was found in keycloak before version 13.0.0.
network
low complexity
redhat CWE-863
5.5
2020-12-15 CVE-2020-14302 Authentication Bypass by Capture-replay vulnerability in Redhat Keycloak
A flaw was found in Keycloak before 13.0.0 where an external identity provider, after successful authentication, redirects to a Keycloak endpoint that accepts multiple invocations with the use of the same "state" parameter.
network
low complexity
redhat CWE-294
4.0
2020-12-15 CVE-2020-10770 Server-Side Request Forgery (SSRF) vulnerability in Redhat Keycloak
A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter request_uri.
network
low complexity
redhat CWE-918
5.3
2020-09-16 CVE-2020-1694 Incorrect Permission Assignment for Critical Resource vulnerability in Redhat Keycloak
A flaw was found in all versions of Keycloak before 10.0.0, where the NodeJS adapter did not support the verify-token-audience.
network
low complexity
redhat CWE-732
4.0