-
Notifications
You must be signed in to change notification settings - Fork 7.7k
Security: keycloak/keycloak
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Impersonation via logout token exchangeGHSA-7fpj-9hr8-28vh published
Apr 17, 2024 by abstractjLow -
XSS via assertion consumer service URL in SAML POST-binding flowGHSA-8rmm-gm28-pj8q published
Apr 17, 2024 by abstractjHigh -
Path traversal in the redirect validationGHSA-mrv8-pqfj-7gp5 published
Apr 17, 2024 by abstractjHigh -
Authorization BypassGHSA-46c8-635v-68r2 published
Apr 17, 2024 by abstractjModerate -
Log Injection during WebAuthn authentication or registrationGHSA-j628-q885-8gr5 published
Apr 17, 2024 by abstractjLow -
keycloak-core: open redirect via "form_post.jwt" JARM response modeGHSA-9vm7-v8wj-3fqw published
Jan 22, 2024 by abstractjModerate -
The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restrictedGHSA-mpwq-j3xf-7m5w published
Dec 19, 2023 by abstractjHigh -
Reflected XSS via wildcard in OIDC redirect_uriGHSA-cvg2-7c3j-g36j published
Dec 18, 2023 by abstractjModerate -
Plaintext Storage of User PasswordGHSA-5q66-v53q-pm35 published
Sep 12, 2023 by abstractjHigh -
Secondary factor bypass in step-up authenticationGHSA-4f53-xh3v-g8x4 published
Apr 17, 2024 by abstractjModerate