Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Keycloak vulnerable to uncontrolled resource consumption

GHSA-r32r-3977-cgc3 · CVE-2014-3651

Published · Modified

Description

JBoss KeyCloak versions prior to 1.0.3.Final allow remote attackers to create a denial of service (resource consumption) by supplying a large value in the size parameter to auth/qrcode, related to QR code generation.

Ready to move

Start Securing

Free, no credit card | First findings in minutes