Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2vp8-jv5v-6qh6

Опубликовано: 13 июл. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Allocation of resources without limits or throttling in keycloak-model-infinispan

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

Пакеты

Наименование

org.keycloak:keycloak-model-infinispan

maven
Затронутые версииВерсия исправления

< 14.0.0

14.0.0

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
около 5 лет назад

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

CVSS3: 7.5
nvd
больше 4 лет назад

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

CVSS3: 7.5
debian
больше 4 лет назад

A flaw was found in keycloak-model-infinispan in keycloak versions bef ...

EPSS

Процентиль: 64%
0.00468
Низкий

7.5 High

CVSS3

Дефекты

CWE-770