Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

keycloak — Vulnerabilities & Security Advisories 89

All 89 CVE vulnerabilities found in keycloak, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive vulnerability aggregation for KeyCloak, an open-source identity and access management solution developed by Red Hat, focusing on common software weaknesses. It collects and catalogs security issues identified within the KeyCloak ecosystem, covering advisories and reports issued over the past five years. By centralizing this data, the page allows users to track Red Hat's security advisories as they relate specifically to KeyCloak, understand the broader implications of specific weakness classes such as injection or authentication bypass within identity management contexts, and look up the complete vulnerability history of the product to assess its security posture over time. The information is organized to facilitate efficient risk assessment for system administrators and security analysts who rely on KeyCloak for enterprise authentication and authorization. This resource does not provide mitigation steps but serves as a factual reference for known defects and their classification. Users can filter data by severity, publication date, or vulnerability type to identify relevant threats affecting their deployment. The aggregation aims to improve transparency and help stakeholders make informed decisions regarding upgrades, patching, and configuration hardening based on historical vulnerability trends. All data is sourced from official vendor disclosures and recognized security databases, ensuring accuracy and reliability for technical review.

Vendor: JBoss

CVE IDTitleCVSSSeverityPublished
CVE-2020-1728 Red Hat Keycloak 安全特征问题漏洞 CWE-358 4.8 Medium2020-04-06
CVE-2020-1744 Red Hat Keycloak 信息泄露漏洞 CWE-755 5.6 Medium2020-03-24
CVE-2020-1731 Red Hat Keycloak operator 安全漏洞 CWE-341 9.1 Critical2020-03-02
CVE-2020-1697 Red Hat Keycloak 跨站脚本漏洞 CWE-79 6.1 Medium2020-02-10
CVE-2019-14820 Red Hat Keycloak 信息泄露漏洞 CWE-200 7.5 -2020-01-08
CVE-2019-14837 Red Hat Keycloak 安全漏洞 CWE-547 8.1 -2020-01-07
CVE-2019-14910 Red Hat Keycloak 授权问题漏洞 CWE-287 9.8 -2019-12-05
CVE-2019-14909 Red Hat Keycloak 授权问题漏洞 CWE-287 8.6 -2019-12-04
CVE-2014-3655 Red Hat Keycloak 跨站请求伪造漏洞 6.5 -2019-11-13
CVE-2019-10201 Red Hat Keycloak 授权问题漏洞 CWE-592 8.1 -2019-08-14
CVE-2019-10199 红帽 Red Hat Keycloak 跨站请求伪造漏洞 CWE-352 8.8 -2019-08-14
CVE-2019-3875 Red Hat Keycloak 信任管理问题漏洞 CWE-345 6.5 -2019-06-12
CVE-2019-10157 Red Hat Keycloak Node.js adapter 授权问题漏洞 CWE-345 5.5 -2019-06-12
CVE-2019-3868 Red Hat Keycloak 信息泄露漏洞 CWE-200 3.8 -2019-04-24
CVE-2018-14637 Red Hat keycloak 安全漏洞 CWE-287 5.9 -2018-11-30
CVE-2018-14658 Red Hat JBoss KeyCloak 安全漏洞 CWE-601 6.1 -2018-11-13
CVE-2018-14657 Red Hat Keycloak 安全特征问题漏洞 CWE-307 9.4 -2018-11-13
CVE-2018-14655 Red Hat Keycloak 跨站脚本漏洞 CWE-79 5.4 -2018-11-13
CVE-2016-8609 Red Hat keycloak 授权问题漏洞 CWE-384 8.8 -2018-08-01
CVE-2018-10894 Red Hat Keycloak 安全漏洞 CWE-345 8.1 -2018-08-01
CVE-2017-2646 Red Hat keycloak 安全漏洞 CWE-835 7.5 -2018-07-27
CVE-2017-2582 Red Hat Picketlink和KeyCloak 信息泄露漏洞 CWE-201 7.5 -2018-07-26
CVE-2018-10912 Red Hat keycloak 安全漏洞 CWE-835 4.9 -2018-07-23
CVE-2017-2585 Red Hat Keycloak 信息泄露漏洞 5.9 -2018-03-12
CVE-2016-8629 Red Hat Keycloak 权限许可和访问控制漏洞 CWE-284 7.1 -2018-03-12
CVE-2017-12161 Red Hat keycloak 安全漏洞 CWE-602 8.8 -2018-02-21
CVE-2017-12160 Keycloak oauth 安全漏洞 CWE-285 7.2 -2017-10-26
CVE-2017-12159 Red Hat Keycloak 安全漏洞 CWE-613 6.5 -2017-10-26
CVE-2017-12158 Red Hat Keycloak 跨站脚本漏洞 CWE-444 5.4 -2017-10-26

All 89 known CVE vulnerabilities affecting keycloak with full Chinese analysis, references, and POCs where available.