Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-6841

Опубликовано: 10 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

Отчет

Red Hat has evaluated this vulnerability and it only affects the Red Hat Single Sign-On (RHSSO).

Меры по смягчению последствий

This CVE is mitigated by the 'User Profile' functionality, which was introduced in Keycloak 24. This feature introduces additional validation which prevents this vulnerability from being exploited.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of QuarkuskeycloakNot affected
Red Hat Fuse 7keycloakNot affected
Red Hat Mobile Application Platform 4keycloakNot affected
Red Hat OpenShift Application RuntimeskeycloakNot affected
Red Hat Process Automation 7keycloakNot affected
Red Hat Single Sign-On 7rh-sso7-keycloakFix deferred
Red Hat support for Spring BootkeycloakNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-231
https://bugzilla.redhat.com/show_bug.cgi?id=2254714keycloak: Amount of attributes per object is not limited and it may lead to DOS

EPSS

Процентиль: 69%
0.00613
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

CVSS3: 7.5
debian
больше 1 года назад

A denial of service vulnerability was found in keycloak where the amou ...

CVSS3: 6.5
github
больше 1 года назад

Keycloak Denial of Service vulnerability

EPSS

Процентиль: 69%
0.00613
Низкий

7.5 High

CVSS3