6
I Use This!
Activity Not Available
Analyzed about 1 month ago. based on code collected 2 months ago.
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2024-7341 High Sep 09, 2024 A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, more...
24.0.10, 24.0.9, 24.0.8, 22.0.13, 24.0.7, 22.0.12, 25.0.2, 24.0.6, 25.0.1, 25.0.0
BDSA-2024-9788 Medium Dec 18, 2024 Keycloak is vulnerable to cleartext transmission of sensitive information due to a malfunction in the `KC_CACHE_EMBEDDED_MTLS_ENABLED` environment opti more...
BDSA-2024-9052 Medium Nov 25, 2024 Keycloak is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. This could allow an attacker to exploit costly DN more...
BDSA-2024-9041 Medium Nov 25, 2024 A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process more...
BDSA-2024-6549 Medium Sep 20, 2024 **A vulnerability has been reported in Keycloak with the following commentary:** A flaw exists in the SAML signature validation method within the Key more...
BDSA-2024-6548 Medium Sep 20, 2024 **A vulnerability has been reported in Keycloak with the following commentary:** A misconfiguration flaw was found in Keycloak. This issue can allow more...
BDSA-2024-6182 Medium Sep 16, 2024 **A vulnerability has been reported in org.keycloak:keycloak-core with the following commentary:** A denial of service vulnerability was found in key more...