HIGH 7.5 Maven
Keycloak vulnerable to uncontrolled resource consumption
GHSA-r32r-3977-cgc3 · CVE-2014-3651
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
JBoss KeyCloak versions prior to 1.0.3.Final allow remote attackers to create a denial of service (resource consumption) by supplying a large value in the size parameter to auth/qrcode, related to QR code generation.
Ready to move
Start Securing
Free, no credit card | First findings in minutes