Permissions, Privileges, and Access Controls in Keycloak - CVE-2024-1249
Published: April 17, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to "checkLoginIframe" allows unvalidated cross-origin messages. A remote attacker can send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
Affected software
Red Hat Single Sign-On
Dell Data Protection Central
Red Hat OpenShift Serverless
AMQ Broker
rh-sso7-keycloak (Red Hat package)
How to mitigate CVE-2024-1249
Red Hat Single Sign-On - update to 7.6.8
Dell Data Protection Central - update to 19.12.0-2
Red Hat OpenShift Serverless - update to 1.33.0
AMQ Broker - update to 7.12.0
rh-sso7-keycloak (Red Hat package) - addressed in versions 18.0.13-1.redhat_00001.1.el7sso, 18.0.13-1.redhat_00001.1.el8sso, 18.0.13-1.redhat_00001.1.el9sso
External References
Related Security Bulletins
- Multiple vulnerabilities in Keycloak
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 7
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 8
- Multiple vulnerabilities in Red Hat Single Sign-On 7.6 on RHEL 9
- Multiple vulnerabilities in AMQ Broker 7.12
- Multiple vulnerabilities in Red Hat OpenShift Serverless 1
- Dell Data Protection Central update for third-party component