CVE-2024-11734
Org.keycloak:keycloak-quarkus-server: denial of service in keycloak server via security headers
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.
Se encontró una vulnerabilidad de denegación de servicio en Keycloak que podría permitir que un usuario administrativo con derecho a cambiar la configuración del dominio interrumpa el servicio. Esta acción se realiza modificando cualquiera de los encabezados de seguridad e insertando nuevas líneas, lo que hace que el servidor de Keycloak escriba en una solicitud que ya se ha finalizado, lo que provoca el fracaso de dicha solicitud.
New images are available for Red Hat build of Keycloak 26.0.8 and Red Hat build of Keycloak 26.0.8 Operator, running on OpenShift Container Platform. Issues addressed include a denial of service vulnerability.
CVSS Scores
SSVC
- Decision:Track
Timeline
- 2024-11-26 CVE Reserved
- 2025-01-14 CVE Published
- 2025-03-19 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-693: Protection Mechanism Failure
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2025:0299 | 2025-01-14 | |
https://access.redhat.com/errata/RHSA-2025:0300 | 2025-01-14 | |
https://access.redhat.com/security/cve/CVE-2024-11734 | 2025-01-13 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2328846 | 2025-01-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Redhat Search vendor "Redhat" | Build Keycloak Search vendor "Redhat" for product "Build Keycloak" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Build Of Keycloak Search vendor "Redhat" for product "Build Of Keycloak" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jboss Enterprise Application Platform Search vendor "Redhat" for product "Jboss Enterprise Application Platform" | * | - |
Affected
| ||||||
Redhat Search vendor "Redhat" | Jbosseapxp Search vendor "Redhat" for product "Jbosseapxp" | * | - |
Affected
|