Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-2559

Опубликовано: 20 мар. 2025
Источник: redhat
CVSS3: 4.9

Описание

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7keycloak-servicesFix deferred
Red Hat Build of Keycloakkeycloak-servicesFixedRHSA-2025:433629.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-operator-bundleFixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9FixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9-operatorFixedRHSA-2025:433529.04.2025

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2353868org.keycloak/keycloak-services: JWT Token Cache Exhaustion Leading to Denial of Service (DoS) in Keycloak

4.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
nvd
около 1 года назад

A flaw was found in Keycloak. When the configuration uses JWT tokens for authentication, the tokens are cached until expiration. If a client uses JWT tokens with an excessively long expiration time, for example, 24 or 48 hours, the cache can grow indefinitely, leading to an OutOfMemoryError. This issue could result in a denial of service condition, preventing legitimate users from accessing the system.

CVSS3: 4.9
debian
около 1 года назад

A flaw was found in Keycloak. When the configuration uses JWT tokens f ...

CVSS3: 4.9
github
около 1 года назад

Keycloak Denial of Service (DoS) Vulnerability via JWT Token Cache

4.9 Medium

CVSS3