📦 Single Sign On

by Redhat

🔍 What is Single Sign On?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-4361

CRITICAL CVSS 10.0 Jul 7, 2023

Keycloak has a cross-site scripting (XSS) vulnerability in SAML and OIDC providers where attackers can inject malicious scripts via AssertionConsumerServiceURL or redirect_uri parameters. This allows ...

CVE-2025-9784

HIGH CVSS 7.5 Sep 2, 2025

This vulnerability in Undertow allows malicious clients to send malformed requests that trigger server-side stream resets without incrementing abuse counters. This 'MadeYouReset' attack enables denial...

CVE-2023-6841

HIGH CVSS 7.5 Sep 10, 2024

This CVE describes a denial-of-service vulnerability in Keycloak where attackers can send repeated HTTP requests with excessive attributes, causing resource exhaustion by forcing the application to pr...

CVE-2024-7341

HIGH CVSS 7.1 Sep 9, 2024

This CVE describes a session fixation vulnerability in Keycloak's SAML adapters where session IDs aren't regenerated during login, even when configured to do so. Attackers who hijack a session before ...

CVE-2024-1132

HIGH CVSS 8.1 Apr 17, 2024

This vulnerability in Keycloak allows attackers to bypass URL validation in redirects when clients use wildcards in Valid Redirect URIs. Attackers can construct malicious requests to access unauthoriz...

CVE-2023-6291

HIGH CVSS 7.1 Jan 26, 2024

This vulnerability in Keycloak's redirect_uri validation logic allows attackers to bypass host restrictions and steal access tokens. Attackers can then impersonate legitimate users. All Keycloak deplo...

CVE-2023-6563

HIGH CVSS 7.7 Dec 14, 2023

An unconstrained memory consumption vulnerability in Keycloak allows attackers to cause denial of service by triggering excessive resource usage when accessing the admin UI's consents tab in environme...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2022-4137

HIGH CVSS 8.1 Sep 25, 2023

This reflected cross-site scripting (XSS) vulnerability in Keycloak's 'oob' OAuth endpoint allows attackers to inject malicious scripts via crafted links, potentially compromising user details when vi...

CVE-2023-1108

HIGH CVSS 7.5 Sep 14, 2023

CVE-2023-1108 is a denial-of-service vulnerability in Undertow's SSL/TLS implementation where an infinite loop in the handshake process can crash the server. This affects any system running vulnerable...

CVE-2022-4492

HIGH CVSS 7.5 Feb 23, 2023

CVE-2022-4492 is a server certificate validation bypass vulnerability in Undertow HTTP client. It allows attackers to perform man-in-the-middle attacks by presenting invalid certificates that should b...

CVE-2021-3717

HIGH CVSS 7.8 May 24, 2022

CVE-2021-3717 is a security flaw in Wildfly's elytron configuration that incorrectly handles JBOSS_LOCAL_USER challenges. This allows any local user on the machine to gain JBOSS_LOCAL_USER access, pot...

CVE-2021-3461

HIGH CVSS 7.1 Apr 1, 2022

This vulnerability in Keycloak allows session persistence after logout when using external SAML identity providers with specific Principal Type configurations. Attackers could maintain access to user ...

CVE-2022-0853

HIGH CVSS 7.5 Mar 11, 2022

CVE-2022-0853 is a memory leak vulnerability in JBoss client applications that repeatedly use UserTransaction. This allows attackers to cause information leakage by exhausting memory resources. Organi...

CVE-2021-4104

HIGH CVSS 7.5 Dec 14, 2021

CVE-2021-4104 is a deserialization vulnerability in Log4j 1.2's JMSAppender that allows remote code execution when attackers can modify Log4j configuration files. This affects systems running Log4j 1....

CVE-2023-1932

MEDIUM CVSS 6.1 Nov 7, 2024

This vulnerability allows attackers to bypass Hibernate Validator's SafeHtml validation by omitting tag endings with less-than characters. This enables HTML injection and Cross-Site Scripting (XSS) at...

CVE-2022-1274

MEDIUM CVSS 5.4 Mar 29, 2023

CVE-2022-1274 is an HTML injection vulnerability in Keycloak's execute-actions-email endpoint that allows attackers to inject arbitrary HTML into emails sent to users. This affects all Keycloak deploy...

CVE-2022-2237

MEDIUM CVSS 6.1 Mar 27, 2023

CVE-2022-2237 is an open redirect vulnerability in Keycloak's Node.js adapter checkSso function. This allows attackers to redirect users to malicious websites after authentication. Organizations using...