PT-2025-1683 · Red Hat+1 · Keycloak+1

·

CVE-2024-11734

·

Published

2025-01-13

·

Updated

2025-11-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A denial of service issue was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request. Service disruption may happen, and users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
CVE-2024-11734
GHSA-W3G8-R9GW-QRH8

Affected Products

Alt Linux
Keycloak