QID 982010
QID 982010: Java (maven) Security Update for org.keycloak:keycloak-model-infinispan (GHSA-2vp8-jv5v-6qh6)
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-2vp8-jv5v-6qh6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-2vp8-jv5v-6qh6 -
github.com/advisories/GHSA-2vp8-jv5v-6qh6
CVEs related to QID 982010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-2vp8-jv5v-6qh6 | org.keycloak:keycloak-model-infinispan |
|