QID 981016
QID 981016: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-jc6q-27mw-p55w)
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jc6q-27mw-p55w for updates pertaining to this vulnerability.
Vendor References
- GHSA-jc6q-27mw-p55w -
github.com/advisories/GHSA-jc6q-27mw-p55w
CVEs related to QID 981016
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jc6q-27mw-p55w | org.keycloak:keycloak-core |
|