Protection Mechanism Failure in Keycloak - CVE-2024-11734
Published: January 13, 2025
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient implementation of security measures. A remote user with the rights to change realm settings can send a specially crafted HTTP request with newline characters in headers and perform a denial of service (DoS) attack.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2024-11734
Red Hat build of Keycloak - update to 26.0.8