Skip to content

[FP]: Keycloak OSGi Adapter falsely flagged for Keycloak Server CVEs #8607

@mnika93

Description

@mnika93

Package URl

pkg:maven/org.keycloak/keycloak-osgi-adapter@18.0.2

CPE

cpe:2.3:a:keycloak:keycloak:18.0.2:::::::*

CVE

CVE-2022-4361, CVE-2023-6291, CVE-2023-6563, CVE-2023-6787, CVE-2024-7341

ODC Integration

{"label" => "CLI"}

ODC Version

12.2.1

Description

Multiple false positives on keycloak-osgi-adapter-18.0.2.jar. The scanner assigns CPE cpe:2.3:a:keycloak:keycloak:18.0.2 and matches all Keycloak CVEs against this JAR. However, this is a
client-side OSGi adapter library used only for OIDC token validation — it is NOT the Keycloak identity server.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions