Vulnerability index

Browse CVEs

16 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Open RedirectCWE-601 × clear
Build Of Keycloak HIGH 8.1
CVE-2026-7504

A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation …

Fix: 26.4.12+
Fix from $1,950 2026-05-19
Build Of Keycloak HIGH 7.3
CVE-2026-3872

A flaw was found in Keycloak. This issue allows an attacker, who controls another path on the same web server, to bypass the allowed path in redirect…

Mitigation only
Fix from $1,950 2026-04-02
Quay MEDIUM 5.4
CVE-2026-2376

A flaw was found in mirror-registry where an authenticated user can trick the system into accessing unintended internal or restricted systems by prov…

Patch available
Fix from $1,600 2026-03-12
Build Of Keycloak MEDIUM 6.1
CVE-2024-8883

A misconfiguration flaw was found in Keycloak. This issue can allow an attacker to redirect users to an arbitrary URL if a 'Valid Redirect URI' is se…

Mitigation only
Fix from $1,600 2024-09-19
Build Of Keycloak MEDIUM 6.1
CVE-2024-7260

An open redirect vulnerability was found in Keycloak. A specially crafted URL can be constructed where the referrer and referrer_uri parameters are m…

Fix: 24.0.7+
Fix from $1,600 2024-09-09
Keycloak HIGH 7.1
CVE-2023-6291

A flaw was found in the redirect_uri validation logic in Keycloak. This issue may allow a bypass of otherwise explicitly allowed hosts. A successful …

Fix: 22.0.7+
Fix from $1,950 2024-01-26
Keycloak MEDIUM 6.1
CVE-2023-6927

A flaw was found in Keycloak. This issue may allow an attacker to steal authorization codes or tokens from clients using a wildcard in the JARM respo…

Mitigation only
Fix from $1,600 2023-12-18
Keycloak Node.js Adapter MEDIUM 6.1
CVE-2022-2237

A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso functio…

Mitigation only
Fix from $1,600 2023-03-27
Openstack Platform MEDIUM 6.1
CVE-2021-3654EPSS 27%

A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.

Fix: 21.2.3 / 22.2.3+
Fix from $1,600 2022-03-02
Mobile Application Platform MEDIUM 6.1
CVE-2020-1723

A flaw was found in Keycloak Gatekeeper (Louketo). The logout endpoint can be abused to redirect logged-in users to arbitrary web pages. Affected ver…

Mitigation only
Fix from $1,600 2021-01-28
Ovirt Engine MEDIUM 5.3
CVE-2020-10775

An Open redirect vulnerability was found in ovirt-engine versions 4.4 and earlier, where it allows remote attackers to redirect users to arbitrary we…

Fix: after 4.4
Fix from $1,600 2020-08-24
Keycloak MEDIUM 6.1
CVE-2014-3652

JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.

Patch available
Fix from $1,600 2019-12-15
Keycloak MEDIUM 6.1
CVE-2018-14658

A flaw was found in JBOSS Keycloak 3.2.1.Final. The Redirect URL for both Login and Logout are not normalized in org.keycloak.protocol.oidc.utils.Red…

Mitigation only
Fix from $1,600 2018-11-13
Enterprise Linux Desktop MEDIUM 6.5
CVE-2017-15419

Insufficient policy enforcement in Resource Timing API in Google Chrome prior to 63.0.3239.84 allowed a remote attacker to infer browsing history by …

Fix: 63.0.3239.84+
Fix from $1,600 2018-08-28
Enterprise Linux HIGH 7.4
CVE-2017-3085

Adobe Flash Player versions 26.0.0.137 and earlier have a security bypass vulnerability that leads to information disclosure when performing URL redi…

Fix: after 26.0.0.137
Fix from $1,950 2017-08-11
Network Satellite MEDIUM 6.5
CVE-2011-1594

A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerability allows remote attackers to redirect users to ar…

Patch available
Fix from $1,600 2014-02-05