Back to Database
Status published
Medium
CVE-2019-14820
It was found that keycloak before version 8.0.0 exposes internal...
Vulnerability Description
It was found that keycloak before version 8.0.0 exposes internal adapter endpoints in org.keycloak.constants.AdapterConstants, which can be invoked via a specially-crafted URL. This vulnerability could allow an attacker to access unauthorized information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-14820
Credits & Attribution
No credits recorded in the NVD database.
More from keycloak
View All →CVE-2022-4361
Keycloak, an open-source identity and access management solution, has a...
Critical
10
CVE-2019-14832
A flaw was found in the Keycloak REST API before...
Medium
5
CVE-2014-3709
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote...
High
8.8
CVE-2014-3651
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a...
High
7.5
Affected Vendor
keycloak
View all reports →Affected Software
keycloak
Vulnerable Versions:
fixed in 8.0.0
Timeline
Official Publish:
January 8th, 2020
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N