Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jc6q-27mw-p55w

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Keycloak vulnerable to infinite loop based Denial of Service

When Keycloak versions prior to 2.5.5 receive a Logout request with an Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in an infinite loop. An attacker could use this flaw to conduct denial of service attacks.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.5.5

2.5.5

EPSS

Процентиль: 77%
0.01854
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
redhat
больше 9 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.

CVSS3: 7.5
nvd
около 8 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.

CVSS3: 7.5
debian
около 8 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request ...

EPSS

Процентиль: 77%
0.01854
Низкий

7.5 High

CVSS3

Дефекты

CWE-835