Maven package intelligence

org.keycloak:keycloak-core Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the Maven package org.keycloak:keycloak-core, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting org.keycloak:keycloak-core
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
org.keycloak:keycloak-core KEVs with sensor-observed exploitation activity

Review org.keycloak:keycloak-core exploitation against the versions you run

One of the one exploited org.keycloak:keycloak-core vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested org.keycloak:keycloak-core vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2020-10770

A flaw was found in Keycloak before 13.0.0, where it is possible to force the server to call out an unverified URL using the OIDC parameter...

Beyond CISA 15 Dec 2020

Recurring weakness patterns

Server-Side Request Forgery (SSRF) account for mapped occurrences across this org.keycloak:keycloak-core KEV portfolio.

Browse all KEVs →