Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-11734

Опубликовано: 14 янв. 2025
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

EPSS

Процентиль: 15%
0.00048
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 6.5
redhat
около 1 года назад

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

CVSS3: 6.5
debian
около 1 года назад

A denial of service vulnerability was found in Keycloak that could all ...

CVSS3: 6.5
github
около 1 года назад

Denial of Service in Keycloak Server via Security Headers

EPSS

Процентиль: 15%
0.00048
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-693