Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Allocation of Resources Without Limits or Throttling in Keycloak

GHSA-52rg-hpwq-qp56 · CVE-2020-10758

Published · Modified

Description

A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

Ready to move

Start Securing

Free, no credit card | First findings in minutes