-
Notifications
You must be signed in to change notification settings - Fork 7.7k
Security: keycloak/keycloak
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Impersonation and lockout possible through incorrect handling of email trustGHSA-c7xw-p58w-h6fj published
Jul 18, 2023 by stianstModerate -
Client Spoofing within the Keycloak Device Authorisation GrantGHSA-f5h4-wmp5-xhg6 published
Jun 28, 2023 by abstractjModerate -
Untrusted Certificate ValidationGHSA-5cc8-pgp5-7mpm published
Jun 28, 2023 by abstractjLow -
Improper Client Certificate Validation for OAuth/OpenID clientsGHSA-3qh5-qqj2-c78f published
Jun 28, 2023 by abstractjHigh -
User impersonation via stolen UUID codeGHSA-9g98-5mj6-f9mv published
Mar 2, 2023 by stianstHigh -
XSS on impersonation under specific circumstancesGHSA-w354-2f3c-qvg9 published
Feb 27, 2023 by abstractjModerate -
Lack of validation of access token on client registrations endpointGHSA-v436-q368-hvgg published
Jan 12, 2023 by abstractjLow -
Session takeover with OIDC offline refreshtokensGHSA-97g8-xfvw-q4hg published
Dec 13, 2022 by abstractjModerate -
Path traversal via double URL encodingGHSA-g8q8-fggx-9r3q published
Dec 13, 2022 by abstractjHigh -
Reflected XSS on OpenID connect login serviceGHSA-9hhc-pj4w-w5rv published
Feb 27, 2023 by abstractjHigh