keycloak-quarkus-server vulnerabilities
CVEs whose affected-version data names the keycloak-quarkus-server package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2024-9666Medium· 4.7A vulnerability was found in the Keycloak Server
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accep…
CVE-2024-10492Low· 2.7A vulnerability was found in Keycloak
A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order t…
CVE-2024-10451Medium· 5.9A flaw was found in Keycloak
A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosu…