Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Search results
CVE-LINKED INVENTORY28 SECURITY RECORDS

Red Hat, Inc.

keycloak

Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.

Lifecycle evidence status

Official registry publication history is available at keycloak, but registry activity is not a publisher support boundary.

A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.

CVE-observed version history

CVEPublishedAffected versionsFixed version informationPublisher evidence
CVE-2020-14366 9 Nov 2020 before (excluding) 12.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1758 15 May 2020 keycloak versions before 10.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1714 13 May 2020 before 11.0.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2020-1718 12 May 2020 All versions before 8.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1724 11 May 2020 All versions before 9.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1698 11 May 2020 All versions before 9.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1744 24 Mar 2020 all keycloak versions prior to 9.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1731 2 Mar 2020 all versions of keycloak operator before keycloak operator 8.0.2 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2020-1697 10 Feb 2020 All versions before 9.0.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-14837 7 Jan 2020 before 8.0.0 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-10201 14 Aug 2019 up to keycloak 6.0.1 No fixed version is explicitly recorded in the structured CVE data. Update reference ↗
CVE-2019-10199 14 Aug 2019 up to keycloak 6.0.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-3875 12 Jun 2019 6.0.2 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2019-10157 12 Jun 2019 4.8.3 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2019-3868 24 Apr 2019 affects up to 6.0.0 version No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-14658 13 Nov 2018 3.2.1.Final No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-14657 13 Nov 2018 4.2.1.Final, 4.3.0.Final No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-14655 13 Nov 2018 3.4.3.Final, 4.0.0.Beta2, 4.3.0.Final No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2018-10894 1 Aug 2018 3.4.3.Final An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2016-8609 1 Aug 2018 2.3.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-2646 27 Jul 2018 2.5.5 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-2582 26 Jul 2018 2.5.1 An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2017-2585 12 Mar 2018 2.5.1 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2016-8629 12 Mar 2018 2.4.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-12161 21 Feb 2018 before 3.4.2.Final An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release. Update reference ↗
CVE-2017-12160 26 Oct 2017 3.4.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-12159 26 Oct 2017 3.4.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record
CVE-2017-12158 26 Oct 2017 3.4.0 No fixed version is explicitly recorded in the structured CVE data. Use CVE record

How this record is maintained

The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.