-
Notifications
You must be signed in to change notification settings - Fork 7.7k
Security: keycloak/keycloak
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Cross-site scripting when validating URI-schemes on SAML and OIDCGHSA-3p62-6fjh-3p5h published
Jun 28, 2023 by abstractjLow -
LDAP Injection on UsernameForm LoginGHSA-8hc5-rmgf-qx6p published
Nov 29, 2023 by stianstLow -
SAML javascript protocol mapper: Uploading of scripts through admin consoleGHSA-wf7g-7h6h-678v published
Sep 22, 2022 by abstractjLow -
Stored XSS when loading default rolesGHSA-w9mf-83w3-fv49 published
Sep 22, 2022 by abstractjModerate -
HTML Injection in Keycloak Admin REST APIGHSA-m4fv-gm5m-4725 published
Feb 27, 2023 by abstractjModerate -
Privilege escalation vulnerability on Token Exchange featureGHSA-75p6-52g3-rqc8 published
Apr 25, 2022 by abstractjModerate -
Keycloak is vulnerable to IDN homograph attackGHSA-mwm4-5qwr-g9pf published
Apr 25, 2022 by abstractjLow -
ECP SAML binding bypasses authentication flowsGHSA-4pc7-vqv5-5r3v published
Apr 25, 2022 by abstractjModerate -
Stored XSS in groups dropdownGHSA-755v-r4x4-qf7m published
Nov 24, 2022 by abstractjModerate -
Incorrect authorization allows unpriviledged users to create other usersGHSA-83x4-9cwr-5487 published
Dec 20, 2021 by stianstHigh