Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
Keycloak
HIGH 8.8
CVE-2017-12161
It was found that keycloak before 3.4.2 final would permit misuse of a client-side /etc/hosts entry to spoof a URL in a password reset request. An at…
Fix: 3.4.2+
Fix from $1,950
2018-02-21
Keycloak
HIGH 7.5
CVE-2014-3651
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter…
Fix: 1.0.3+
Fix from $1,950
2017-12-29
Keycloak
HIGH 8.8
CVE-2014-3709
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site…
Fix: after 1.0.2.final
Fix from $1,950
2017-10-18
Keycloak Nodejs Auth Utils
CRITICAL 9.8
CVE-2017-7474
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authenti…
Mitigation only
Fix from $2,300
2017-05-12