Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-1249

Опубликовано: 17 апр. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
keycloakitppackage

EPSS

Процентиль: 33%
0.00131
Низкий

Связанные уязвимости

CVSS3: 7.4
redhat
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
nvd
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
github
почти 2 года назад

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

EPSS

Процентиль: 33%
0.00131
Низкий