Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Spsh-1635 #109
base: main
Are you sure you want to change the base?
Spsh-1635 #109
Changes from 4 commits
ef67b1a
30f21c0
78581a2
8617454
d2727cb
64d1de9
File filter
Filter by extension
Conversations
Jump to
There are no files selected for viewing
Check warning
Code scanning / Trivy
guava: insecure temporary directory creation Medium
Check notice
Code scanning / Trivy
guava: local information disclosure via temporary directory created with unsafe permissions Low
Check warning
Code scanning / Trivy
okio: GzipSource class improper exception handling Medium
Check notice
Code scanning / Trivy
keycloak-core: DoS via account lockout Low
Check failure
Code scanning / Trivy
keycloak: Unguarded admin REST API endpoints allows low privilege users to use administrative functionalities High
Check failure
Code scanning / Trivy
keycloak: exposure of sensitive information in Pushed Authorization Requests (PAR) KC_RESTART cookie High
Check warning
Code scanning / Trivy
keycloak: potential bypass of brute force protection Medium
Check warning
Code scanning / Trivy
keycloak-core: Open Redirect on Account page Medium
Check warning
Code scanning / Trivy
keycloak-core: One Time Passcode (OTP) is valid longer than expiration timeSeverity Medium
Check failure
Code scanning / Trivy
wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters High
Check failure
Code scanning / Trivy
keycloak-saml-core: Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak High
Check warning
Code scanning / Trivy
Keycloak: Vulnerable Redirect URI Validation Results in Open Redirec Medium
Check warning
Code scanning / Trivy
One Time Passcode (OTP) is valid longer than expiration timeSeverity Medium
Check failure
Code scanning / Trivy
Improper Verification of SAML Responses Leading to Privilege Escalation in Keycloak High
Check failure
Code scanning / Trivy
Session fixation in Elytron SAML adapters High
Check warning
Code scanning / Trivy
Vulnerable Redirect URI Validation Results in Open Redirect Medium
Check warning
Code scanning / Trivy
netty: Denial of Service attack on windows app using Netty Medium
Check failure
Code scanning / Trivy
keycloak-core: mTLS passthrough High
Check warning
Code scanning / Trivy
org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process Medium
Check notice
Code scanning / Trivy
keycloak-quarkus-server: Keycloak path trasversal Low
Check warning
Code scanning / Trivy
org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability Medium
Check warning
Code scanning / Trivy
org.keycloak:keycloak-services: Keycloak Denial of Service Medium
Check failure
Code scanning / Trivy
io.quarkus.http/quarkus-http-core: Quarkus HTTP Cookie Smuggling High
Check warning
Code scanning / Trivy
keycloak: CLI option for encrypted JGroups ignored Medium
Check warning
Code scanning / Trivy
guava: insecure temporary directory creation Medium
Check notice
Code scanning / Trivy
guava: local information disclosure via temporary directory created with unsafe permissions Low
Check warning
Code scanning / Trivy
okio: GzipSource class improper exception handling Medium
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check warning
Code scanning / Trivy
apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 Medium
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check failure
Code scanning / Trivy
apache-commons-io: Possible denial of service attack on untrusted input to XmlStreamReader High
Check warning
Code scanning / Trivy
apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 Medium
Check warning
Code scanning / Trivy
apache-commons-io: Limited path traversal in Apache Commons IO 2.2 to 2.6 Medium
Check failure
Code scanning / Trivy
apache-commons-compress: infinite loop when reading a specially crafted 7Z archive High
Check failure
Code scanning / Trivy
apache-commons-compress: excessive memory allocation when reading a specially crafted 7Z archive High
Check failure
Code scanning / Trivy
apache-commons-compress: excessive memory allocation when reading a specially crafted TAR archive High
Check failure
Code scanning / Trivy
apache-commons-compress: excessive memory allocation when reading a specially crafted ZIP archive High
Check failure
Code scanning / Trivy
commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file High
Check failure
Code scanning / Trivy
commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file High
Check warning
Code scanning / Trivy
commons-compress: OutOfMemoryError unpacking broken Pack200 file Medium
Check failure
Code scanning / Trivy
commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file High
Check warning
Code scanning / Trivy
apache-commons-compress: Denial of service via CPU consumption for malformed TAR file Medium
Check warning
Code scanning / Trivy
commons-compress: OutOfMemoryError unpacking broken Pack200 file Medium
Check failure
Code scanning / Trivy
maven-shared-utils: Command injection via Commandline class Critical
Check failure
Code scanning / Trivy
maven-shared-utils: Command injection via Commandline class Critical
Check failure
Code scanning / Trivy
maven: Block repositories using http by default Critical
Check failure
Code scanning / Trivy
maven: Block repositories using http by default Critical
Check failure
Code scanning / Trivy
maven: Block repositories using http by default Critical
Check failure
Code scanning / Trivy
plexus-archiver: Arbitrary File Creation in AbstractUnArchiver High
Check failure
Code scanning / Trivy
plexus-archiver: Arbitrary File Creation in AbstractUnArchiver High
Check failure
Code scanning / Trivy
plexus-utils: Mishandled strings in Commandline class allow for command injection Critical
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check failure
Code scanning / Trivy
plexus-utils: Mishandled strings in Commandline class allow for command injection Critical
Check failure
Code scanning / Trivy
plexus-utils: Mishandled strings in Commandline class allow for command injection Critical
Check failure
Code scanning / Trivy
plexus-utils: Mishandled strings in Commandline class allow for command injection Critical
Check failure
Code scanning / Trivy
plexus-utils: Mishandled strings in Commandline class allow for command injection Critical
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check failure
Code scanning / Trivy
codehaus-plexus: Directory Traversal High
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check warning
Code scanning / Trivy
codehaus-plexus: XML External Entity (XXE) Injection Medium
Check warning
Code scanning / Trivy
snappy: tries to read outside the bounds of the given byte arrays Medium
Check warning
Code scanning / Trivy
kotlin: vulnerable Java API was used for temporary file and folder creation which could result in information disclosure Medium
Check warning
Code scanning / Trivy
kotlin: Not possible to lock dependencies for Multiplatform Gradle Projects Medium
Check warning
Code scanning / Trivy
keycloak: Amount of attributes per object is not limited and it may lead to DOS Medium
Check failure
Code scanning / Trivy
keycloak-core: mTLS passthrough High
Check warning
Code scanning / Trivy
One Time Passcode (OTP) is valid longer than expiration timeSeverity Medium
Check warning
Code scanning / Trivy
org.keycloak:keycloak-services: Keycloak Denial of Service Medium
Check failure
Code scanning / Trivy
wildfly-elytron: org.keycloak/keycloak-services: session fixation in elytron saml adapters High
Check warning
Code scanning / Trivy
Keycloak: Vulnerable Redirect URI Validation Results in Open Redirec Medium
Check failure
Code scanning / Trivy
Session fixation in Elytron SAML adapters High
Check warning
Code scanning / Trivy
keycloak: potential bypass of brute force protection Medium
Check warning
Code scanning / Trivy
Vulnerable Redirect URI Validation Results in Open Redirect Medium