Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-11734

Опубликовано: 14 янв. 2025
Источник: debian
EPSS Низкий

Описание

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 15%
0.00048
Низкий

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

CVSS3: 6.5
nvd
около 1 года назад

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

CVSS3: 6.5
github
около 1 года назад

Denial of Service in Keycloak Server via Security Headers

EPSS

Процентиль: 15%
0.00048
Низкий