Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Chase Bowman

Researcher fromContract Security
#41653of 53,639
6.5Total CVSS
Vulnerabilities · 1
PT-2025-1683
6.5
2025-01-13
Red Hat · Keycloak · CVE-2024-11734
**Name of the Vulnerable Software and Affected Versions** Keycloak (affected versions not specified) **Description** A denial of service issue was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request. Service disruption may happen, and users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.