Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Allocation of resources without limits or throttling in keycloak-model-infinispan

GHSA-2vp8-jv5v-6qh6 · CVE-2021-3637

Published · Modified

Description

A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

Ready to move

Start Securing

Free, no credit card | First findings in minutes