Описание
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
Ссылки
- Vendor Advisory
- Issue TrackingVendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
EPSS
Процентиль: 69%
0.00613
Низкий
7.5 High
CVSS3
Дефекты
CWE-231
NVD-CWE-noinfo
Связанные уязвимости
CVSS3: 7.5
redhat
больше 1 года назад
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
CVSS3: 7.5
debian
больше 1 года назад
A denial of service vulnerability was found in keycloak where the amou ...
EPSS
Процентиль: 69%
0.00613
Низкий
7.5 High
CVSS3
Дефекты
CWE-231
NVD-CWE-noinfo