CVE-2019-10199: Red Hat Keycloak
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
It was found that Keycloak's account console, up to 6.0.1, did not perform adequate header checks in some requests. An attacker could use this flaw to trick an authenticated user into performing operations via request from an untrusted domain.
Affected products
- Red Hat Keycloak: up to and including 6.0.1
Published 2019-08-14. Last modified 2026-06-17.