Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jc6q-27mw-p55w

Опубликовано: 18 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Keycloak vulnerable to infinite loop based Denial of Service

When Keycloak versions prior to 2.5.5 receive a Logout request with an Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in an infinite loop. An attacker could use this flaw to conduct denial of service attacks.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 2.5.5

2.5.5

EPSS

Процентиль: 66%
0.00503
Низкий

7.5 High

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 7.5
redhat
почти 9 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.

CVSS3: 7.5
nvd
больше 7 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.

CVSS3: 7.5
debian
больше 7 лет назад

It was found that when Keycloak before 2.5.5 receives a Logout request ...

EPSS

Процентиль: 66%
0.00503
Низкий

7.5 High

CVSS3

Дефекты

CWE-835