VendorsRed Hatsingle_sign-on7.6
Vulnerabilities

Red Hat Redhat Single Sign-on 7.6

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2024-1132
Keycloak: path transversal in redirection validation
Published 2024-04-17 · Analyzed
8.1EPSS 0.016
CVE-2022-4137
Keycloak: reflected xss attack
Published 2023-09-25 · Modified
8.1EPSS 0.011
CVE-2023-2585
Keycloak: client access via device auth request spoof
Published 2023-12-21 · Modified
8.1EPSS 0.007
CVE-2023-6563
Keycloak: offline session token dos
Published 2023-12-14 · Modified
7.7EPSS 0.012
CVE-2024-1635
Undertow: out-of-memory error after several closed connections with wildfly-http-client protocol
Published 2024-02-19 · Modified
7.5EPSS 0.046
CVE-2023-3223
Undertow: outofmemoryerror due to @multipartconfig handling
Published 2023-09-27 · Modified
7.5EPSS 0.027
CVE-2023-1108
Undertow: infinite loop in sslconduit during close
Published 2023-09-14 · Modified
7.5EPSS 0.018
CVE-2023-6291
Keycloak: redirect_uri validation bypass
Published 2024-01-26 · Modified
7.1EPSS 0.010
CVE-2023-2422
Keycloak: oauth client impersonation
Published 2023-10-04 · Modified
7.1EPSS 0.005
CVE-2022-3916
Keycloak: session takeover with oidc offline refreshtokens
Published 2023-09-20 · Modified
6.8EPSS 0.010
CVE-2024-8883
Keycloak: vulnerable redirect uri validation results in open redirec
Published 2024-09-19 · Modified
6.1EPSS 0.021