DirectorySecurity Advisories
Sign In
Security Advisories

CGA-vrqx-gvvc-7hch

Published

Last updated

https://images.chainguard.dev/security/CGA-vrqx-gvvc-7hch
Package

keycloak

Latest Update
Fixed
Fixed Version

24.0.3-r0

Aliases
  • CVE-2024-1249
  • GHSA-m6q9-p373-g5q8

Severity

7.4

High

CVSS V3

Summary

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

Description

A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Acknowledgements

Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images