Keycloak-services: keycloak-services: authorization bypass via unnormalized uri matching in pathmatcher
Keycloak security advisories
All 82 advisories Keycloak has published with an identifier, newest first. Severity is the one its publisher assigned, and the fix is the release the publisher named. Nothing on this page is our judgement.
- Advisories
- 8282 carry a CVE
- high
- 28
- medium
- 40
- low
- 14
- Fix in the archive
- 26of 82 matched to a release
- Oldest
- 20 Dec 20214.7 years ago
56 of these point at a version older than anything the archive holds, so there is no release page to link. That is a gap in what was collected, not evidence that the fix does not exist. This page is a copy of what the publisher published, kept for reference. The authoritative source for a security question is the publisher, and an advisory missing from here is not evidence that none exists. What this page does and does not tell you sets out the limits in full.
Newest first
Every productKeycloak-services: keycloak-services: dcr protocol mapper type-swap policy bypass allows privilege escalation
Keycloak-services: keycloak-services: unbounded metric cardinality in user event metrics via request-controlled error text
Keycloak-services: keycloak-services: saml idp-initiated broker login bypasses link-only restriction
Keycloak-services: keycloak-services: saml broker metadata import disables response signature validation
Keycloak-services: keycloak-services: ldap entry-dn user search bypasses configured users dn boundary
Keycloak-services: keycloak-services: default dcr policy allows role forgery via user property mappers
group-admin escalation to realm-admin
Information disclosure through arbitrary filesystem path probing
Cross-site scripting (xss) via case-insensitive uri validation bypass
Attacker can re-enable and take over disabled clients via registration access token
Privilege escalation via improper scope mapping enforcement
Unauthorized access to resources via uma permission ticket bypass
Authorization bypass via incorrect uri comparison
Authentication bypass via jwt algorithm confusion
Keycloak: Unauthorized access via improper validation of encrypted SAML assertions
Deserialization of Untrusted Data in LDAP User Federation
Unable to restrict access to the admin console
Debug default bind address
Keycloak TLS Client-Initiated Renegotiation Denial of Service
Keycloak error_description injection on error pages that can trigger phishing attacks
Variable resolution on imports can expose environment variables
Keycloak SMTP Inject Vulnerability
Phishing attack via email verification step in first login flow
Privilege Escalation in Keycloak Admin Console (FGAPv2 Enabled)
Keycloak hostname verification
Two factor authentication bypass
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak
Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
CLI option for encrypted JGroups ignored
Denial of Service in Keycloak Server via Security Headers
Unrestricted admin use of system and environment variables
Sensitive Data Exposure in Keycloak Build Process
Inefficient Regular Expression Complexity in org.keycloak:keycloak-services
Keycloak Path Traversal Vulnerability Due to External Control of File Name or Path
Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
Session fixation in Elytron SAML adapters
Vulnerable Redirect URI Validation Results in Open Redirect
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak
One Time Passcode (OTP) is valid longer than expiration timeSeverity
Potential bypass of brute force protection
Leak of configured LDAP bind credentials through the Keycloak admin console
DoS via account lockout
Improper input validation on Keycloak allows using email as username
Unguarded admin REST API endpoints allows low privilege users to use administrative functionalities
Exposure of sensitive information in Pushed Authorization Requests (PAR)
Secondary factor bypass in step-up authentication
Log Injection during WebAuthn authentication or registration
Authorization Bypass
Path traversal in the redirect validation
XSS via assertion consumer service URL in SAML POST-binding flow
Impersonation via logout token exchange
Session hijacking via re-authentication
Path transversal in redirection validation
Unvalidated cross-origin messages in checkLoginIframe leads to DDoS
keycloak-core: open redirect via "form_post.jwt" JARM response mode
The redirect_uri validation logic allows for bypassing explicitly allowed hosts that would otherwise be restricted
Reflected XSS via wildcard in OIDC redirect_uri
LDAP Injection on UsernameForm Login
Plaintext Storage of User Password
Impersonation and lockout possible through incorrect handling of email trust
Cross-site scripting when validating URI-schemes on SAML and OIDC
Improper Client Certificate Validation for OAuth/OpenID clients
Untrusted Certificate Validation
Client Spoofing within the Keycloak Device Authorisation Grant
User impersonation via stolen UUID code
HTML Injection in Keycloak Admin REST API
Reflected XSS on OpenID connect login service
XSS on impersonation under specific circumstances
Lack of validation of access token on client registrations endpoint
Path traversal via double URL encoding
Session takeover with OIDC offline refreshtokens
Stored XSS in groups dropdown
Stored XSS when loading default roles
SAML javascript protocol mapper: Uploading of scripts through admin console
Reflected XSS on clients-registrations endpoint
OIDC Logout redirects can happen even if no id_token_hint is provided
ECP SAML binding bypasses authentication flows
Keycloak is vulnerable to IDN homograph attack
Privilege escalation vulnerability on Token Exchange feature
Incorrect authorization allows unpriviledged users to create other users