org.keycloak:keycloak-services vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2023-6544Mediumorg.keycloak:keycloak-services: Keycloak Authorization Bypass vulnerabilityCVE-2023-6717Mediumorg.keycloak:keycloak-services: Keycloak Cross-site Scripting (XSS) via assertion consumer service URL in SAML POST-binding flowCVE-2023-3597Mediumorg.keycloak:keycloak-services: Keycloak secondary factor bypass in step-up authenticationCVE-2024-2419Highorg.keycloak:keycloak-services: Keycloak path traversal vulnerability in the redirect validationCVE-2023-6291Highorg.keycloak:keycloak-services: The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restrictedCVE-2023-6134Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uriCVE-2022-2232Loworg.keycloak:keycloak-ldap-federation: Keycloak vulnerable to LDAP Injection on UsernameForm LoginCVE-2023-2422Highorg.keycloak:keycloak-services: Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clientsCVE-2022-4361Criticalorg.keycloak:keycloak-services: Keycloak vulnerable to cross-site scripting when validating URI-schemes on SAML and OIDCCVE-2023-2585Loworg.keycloak:keycloak-services: Client Spoofing within the Keycloak Device Authorisation GrantCVE-2023-0264Highorg.keycloak:keycloak-services: Keycloak vulnerable to user impersonation via stolen UUID codeCVE-2022-1274Mediumorg.keycloak:keycloak-services: HTML Injection in Keycloak Admin REST APICVE-2022-1438Mediumorg.keycloak:keycloak-services: Keycloak vulnerable to Cross-site ScriptingCVE-2014-3652Mediumorg.keycloak:keycloak-services: JBoss KeyCloak Open RedirectCVE-2014-3655Mediumorg.keycloak:keycloak-services: JBoss KeyCloak is vulnerable to soft token deletion via CSRFCVE-2014-3709Highorg.keycloak:keycloak-services: JBoss Keycloak CSRF VulnerabilityCVE-2018-10894Mediumorg.keycloak:keycloak-saml-adapter-core: Keycloak Authentication ErrorGHSA-MWM4-5QWR-G9PFLoworg.keycloak:keycloak-services: Keycloak is vulnerable to IDN homograph attackCVE-2021-3424Mediumorg.keycloak:keycloak-services: Keycloak is vulnerable to IDN homograph attackCVE-2022-1245Criticalorg.keycloak:keycloak-services: Keycloak vulnerable to privilege escalation on Token Exchange featureCVE-2020-10776Mediumorg.keycloak:keycloak-server-spi-private: Cross-site Scripting in keycloakCVE-2021-4133Highorg.keycloak:keycloak-services: Improper Authorization in Keycloak

Stop the waste.
Protect your environment with Kodem.