Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w97f-w3hq-36g2

Опубликовано: 10 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

Keycloak Denial of Service vulnerability

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited, an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values. The issue is fixed in Keycloak 24 with the introduction of the User Profile feature.

Пакеты

Наименование

org.keycloak:keycloak-core

maven
Затронутые версииВерсия исправления

< 24.0.0

24.0.0

EPSS

Процентиль: 69%
0.00613
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-231

Связанные уязвимости

CVSS3: 7.5
redhat
больше 1 года назад

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

CVSS3: 7.5
nvd
больше 1 года назад

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

CVSS3: 7.5
debian
больше 1 года назад

A denial of service vulnerability was found in keycloak where the amou ...

EPSS

Процентиль: 69%
0.00613
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-231