Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-10270

Опубликовано: 21 нояб. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

Отчет

Red Hat Enterprise Application Platform 8 does not ship or provide the affected component, and so is not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 8keycloak-servicesNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packkeycloak-servicesNot affected
Red Hat Single Sign-On 7keycloak-servicesOut of support scope
Red Hat build of Keycloak 24rhbk/keycloak-operator-bundleFixedRHSA-2024:1017521.11.2024
Red Hat build of Keycloak 24rhbk/keycloak-rhel9FixedRHSA-2024:1017521.11.2024
Red Hat build of Keycloak 24rhbk/keycloak-rhel9-operatorFixedRHSA-2024:1017521.11.2024
Red Hat build of Keycloak 24.0.9FixedRHSA-2024:1017621.11.2024
Red Hat build of Keycloak 26.0rhbk/keycloak-operator-bundleFixedRHSA-2024:1017721.11.2024
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9FixedRHSA-2024:1017721.11.2024
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9-operatorFixedRHSA-2024:1017721.11.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1333
https://bugzilla.redhat.com/show_bug.cgi?id=2321214org.keycloak:keycloak-services: Keycloak Denial of Service

EPSS

Процентиль: 67%
0.01264
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
почти 2 года назад

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

CVSS3: 6.5
debian
почти 2 года назад

A vulnerability was found in the Keycloak-services package. If untrust ...

CVSS3: 6.5
github
почти 2 года назад

org.keycloak:keycloak-services has Inefficient Regular Expression Complexity

CVSS3: 6.5
fstec
почти 2 года назад

Уязвимость функции SearchQueryUtils программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 67%
0.01264
Низкий

6.5 Medium

CVSS3