A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
2020-09-16T16:15:14.797
2024-11-21T04:56:00.697
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | keycloak | < 11.0.1 | Yes |
Application | redhat | openshift_application_runtimes | - | Yes |
Application | redhat | openshift_application_runtimes | 1.0 | Yes |
Application | redhat | single_sign-on | - | Yes |
Application | redhat | single_sign-on | 7.0 | Yes |
Application | redhat | single_sign-on | 7.4 | Yes |