HIGH 7.4 Maven
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
GHSA-m6q9-p373-g5q8 · CVE-2024-1249
Published · Modified
Description
A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
Acknowledgements
Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.
References
- WEB https://github.com/keycloak/keycloak/security/advisories/GHSA-m6q9-p373-g5q8
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-1249
- WEB https://github.com/keycloak/keycloak/commit/9d9817e15a07195f16f554b7f60ee3a918369e26
- WEB https://github.com/keycloak/keycloak/commit/e3598a53678a1e3698e78eb71e04ba10ca32e5e2
- WEB https://access.redhat.com/errata/RHSA-2024:1860
- WEB https://access.redhat.com/errata/RHSA-2024:1861
- WEB https://access.redhat.com/errata/RHSA-2024:1862
- WEB https://access.redhat.com/errata/RHSA-2024:1864
- WEB https://access.redhat.com/errata/RHSA-2024:1866
- WEB https://access.redhat.com/errata/RHSA-2024:1867
- WEB https://access.redhat.com/errata/RHSA-2024:1868
- WEB https://access.redhat.com/errata/RHSA-2024:2945
- WEB https://access.redhat.com/errata/RHSA-2024:4057
- WEB https://access.redhat.com/security/cve/CVE-2024-1249
- WEB https://bugzilla.redhat.com/show_bug.cgi?id=2262918
- PACKAGE https://github.com/keycloak/keycloak
Ready to move
Start Securing
Free, no credit card | First findings in minutes