CVE-2024-1249
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
7.4
HIGH
CVSS 3.1
EPSS 0.45%
描述
A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages. #### Acknowledgements Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.
如何修補 CVE-2024-1249
要修補 CVE-2024-1249,請將受影響套件升級到下列已修補版本。
- —升級至 22.0.10 或更新版本
CVE-2024-1249 正在被利用嗎?
低 — EPSS 為 0.4%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 22.0.10
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H |