PT-2020-5612 · Red Hat · Keycloak

Matt Hamilton

+1

·

Published

2020-09-03

·

Updated

2022-02-09

·

CVE-2020-10758

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 11.0.1
Description The issue is related to a denial of service (DoS) attack, which can be initiated remotely. It is caused by sending requests with a Content-Length header value that exceeds the actual byte count of the request body, potentially leading to unlimited memory allocation. This can allow an attacker to cause a service disruption. The estimated number of potentially affected devices is not specified.
Recommendations For versions prior to 11.0.1, update to version 11.0.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Keycloak server to minimize the risk of exploitation. Avoid sending requests with a Content-Length header value that exceeds the actual byte count of the request body until the issue is resolved.

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01264
CVE-2020-10758
GHSA-52RG-HPWQ-QP56
RHSA-2020:3495
RHSA-2020:3496
RHSA-2020:3497

Affected Products

Keycloak