QID 981051

QID 981051: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-h7j7-pw3v-3v3x)

keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 4.9 severity.
  • CVSS V2 rated as Medium - 4 severity.
  • Solution
    Customers are advised to refer to GHSA-h7j7-pw3v-3v3x for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981051

    Software Advisories
    Advisory ID Software Component Link
    GHSA-h7j7-pw3v-3v3x org.keycloak:keycloak-core URL Logo github.com/advisories/GHSA-h7j7-pw3v-3v3x