QID 980898
QID 980898: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-r32r-3977-cgc3)
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-r32r-3977-cgc3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-r32r-3977-cgc3 -
github.com/advisories/GHSA-r32r-3977-cgc3
CVEs related to QID 980898
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-r32r-3977-cgc3 | org.keycloak:keycloak-core |
|