Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-1249

Опубликовано: 16 апр. 2024
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Отчет

The vulnerability in Keycloak's OIDC component allowing unvalidated cross-origin messages in the "checkLoginIframe" function represents an important severity issue due to its potential to cause significant disruption and resource exhaustion. Exploitation of this flaw can lead to a Denial of Service (DoS) condition, where malicious actors can overwhelm the server with a high volume of requests, impacting availability for legitimate users. The absence of proper origin validation means attackers can exploit this weakness relatively easily, leveraging automated scripts to flood the server within seconds.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Applications 6mta/mta-ui-rhel9Will not fix
Migration Toolkit for Applications 7mta/mta-ui-rhel9Not affected
Red Hat build of Apicurio Registry 2keycloakAffected
Red Hat Data Grid 8keycloakNot affected
Red Hat Decision Manager 7keycloakAffected
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Not affected
Red Hat Fuse 7keycloakNot affected
Red Hat JBoss Data Grid 7keycloakNot affected
Red Hat JBoss Enterprise Application Platform 6keycloakOut of support scope
Red Hat JBoss Enterprise Application Platform 6keycloak-adapter-eap6Out of support scope

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2262918keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkLoginIframe leads to DDoS

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
debian
почти 2 года назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe ...

CVSS3: 7.4
github
почти 2 года назад

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

EPSS

Процентиль: 33%
0.00131
Низкий

7.4 High

CVSS3