Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-52rg-hpwq-qp56

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Allocation of Resources Without Limits or Throttling in Keycloak

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

Пакеты

Наименование

org.keycloak:keycloak-parent

maven
Затронутые версииВерсия исправления

< 11.0.1

11.0.1

EPSS

Процентиль: 79%
0.01947
Низкий

7.5 High

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 7.5
redhat
около 6 лет назад

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

CVSS3: 7.5
nvd
почти 6 лет назад

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

CVSS3: 7.5
debian
почти 6 лет назад

A vulnerability was found in Keycloak before 11.0.1 where DoS attack i ...

CVSS3: 7.5
fstec
почти 6 лет назад

Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с выделением неограниченной памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 79%
0.01947
Низкий

7.5 High

CVSS3

Дефекты

CWE-770