keycloak CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

keycloak vulnerability overview

Aggregates CVE and security vulnerability intelligence across all keycloak-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk cross-site scripting and vendor risk csrf and related problems; some flaws may lead to vendor impact session compromise, affecting vendor surface software deployment scenarios.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2017-12161 It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An attacker could use this flaw to craft a malicious password reset request and gain a valid reset token, leading to information disclosure or further attacks. [email protected] 8.8 1.35% 2018-02-21 2026-06-16
CVE-2014-3651 JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation. [email protected] 7.5 1.63% 2017-12-29 2026-06-16
CVE-2017-12159 It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks. [email protected] 7.5 2.40% 2017-10-26 2026-06-16
CVE-2017-12158 It was found that Keycloak would accept a HOST header URL in the admin console and use it to determine web resource locations. An attacker could use this flaw against an authenticated user to attain reflected XSS via a malicious server. [email protected] 5.4 1.02% 2017-10-26 2026-06-16
CVE-2014-3709 The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection. [email protected] 8.8 0.82% 2017-10-18 2026-06-16
CVE-2017-7474 It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks. [email protected] 9.8 2.54% 2017-05-12 2026-06-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence