Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m6q9-p373-g5q8

Опубликовано: 17 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 7.4

Описание

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Acknowledgements

Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.

Пакеты

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

< 22.0.10

22.0.10

Наименование

org.keycloak:keycloak-services

maven
Затронутые версииВерсия исправления

>= 23.0.0, < 24.0.3

24.0.3

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3

Дефекты

CWE-346

Связанные уязвимости

CVSS3: 7.4
redhat
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
nvd
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
debian
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe ...

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3

Дефекты

CWE-346