PT-2025-1683 · Red Hat+1 · Keycloak+1

Chase Bowman

·

Published

2025-01-13

·

Updated

2025-11-01

·

CVE-2024-11734

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A denial of service issue was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request. Service disruption may happen, and users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
CVE-2024-11734
GHSA-W3G8-R9GW-QRH8

Affected Products

Alt Linux
Keycloak