Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2024-1249

больше 2 лет назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2024-1249

больше 2 лет назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2024-1249

больше 2 лет назад

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe ...

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-m6q9-p373-g5q8

больше 2 лет назад

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2024-1249

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-1249

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-1249

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe ...

CVSS3: 7.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-m6q9-p373-g5q8

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

CVSS3: 7.4
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу