Описание
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
Отчет
Red Hat Enterprise Application Platform 8 does not ship or provide the affected component, and so is not affected by this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | org.keycloak/keycloak-services | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.keycloak/keycloak-services | Not affected | ||
| Red Hat Single Sign-On 7 | org.keycloak/keycloak-services | Out of support scope | ||
| Red Hat build of Keycloak 24 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2024:10175 | 21.11.2024 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9 | Fixed | RHSA-2024:10175 | 21.11.2024 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2024:10175 | 21.11.2024 |
| Red Hat build of Keycloak 24.0.9 | org.keycloak/keycloak-services | Fixed | RHSA-2024:10176 | 21.11.2024 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-operator-bundle | Fixed | RHSA-2024:10177 | 21.11.2024 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9 | Fixed | RHSA-2024:10177 | 21.11.2024 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9-operator | Fixed | RHSA-2024:10177 | 21.11.2024 |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
A vulnerability was found in the Keycloak-services package. If untrust ...
org.keycloak:keycloak-services has Inefficient Regular Expression Complexity
Уязвимость функции SearchQueryUtils программного средства для управления идентификацией и доступом Keycloak, позволяющая нарушителю вызвать отказ в обслуживании
6.5 Medium
CVSS3