writeups.xyz writeups.xyz / Keycloak

Title Vulnerabilities Programs Authors
You Can’t Always Win Racing the (Key)cloak
POST to XSS: Leveraging Pseudo Protocols to Gain JavaScript Evaluation in SSO Flows
mTLS: When certificate authentication is done wrong
Vulnerability Spotlight: CVE-2023-0264
User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264)