PT-2025-1683 · Red Hat+1 · Keycloak+1
Chase Bowman
·
Published
2025-01-13
·
Updated
2025-11-01
·
CVE-2024-11734
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Keycloak (affected versions not specified)
Description
A denial of service issue was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request. Service disruption may happen, and users will be unable to access applications relying on Keycloak, or any of the consoles provided by Keycloak itself on the affected realm.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Keycloak