DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-1249

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-1249

CGA ID

CGA-vrqx-gvvc-7hch

Severity

7.4

High

CVSS V3

Summary

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

Description

A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Acknowledgements

Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.

References

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images