A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
History

Mon, 25 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 Nov 2024 07:45:00 +0000

Type Values Removed Values Added
Title org.keycloak:keycloak-services: Keycloak Denial of Service Org.keycloak:keycloak-services: keycloak denial of service
First Time appeared Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat red Hat Single Sign On
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8
cpe:/a:redhat:jbosseapxp
cpe:/a:redhat:red_hat_single_sign_on:7
Vendors & Products Redhat jboss Enterprise Application Platform
Redhat jbosseapxp
Redhat red Hat Single Sign On
References

Fri, 22 Nov 2024 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
Title org.keycloak:keycloak-services: Keycloak Denial of Service
First Time appeared Redhat
Redhat build Keycloak
Weaknesses CWE-1333
CPEs cpe:/a:redhat:build_keycloak:24
cpe:/a:redhat:build_keycloak:24::el9
cpe:/a:redhat:build_keycloak:26
cpe:/a:redhat:build_keycloak:26.0::el9
Vendors & Products Redhat
Redhat build Keycloak
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-11-25T07:37:04.542Z

Updated: 2024-12-06T14:53:21.983Z

Reserved: 2024-10-23T02:00:58.671Z

Link: CVE-2024-10270

cve-icon Vulnrichment

Updated: 2024-11-25T17:15:04.831Z

cve-icon NVD

Status : Received

Published: 2024-11-25T08:15:03.747

Modified: 2024-11-25T08:15:03.747

Link: CVE-2024-10270

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-11-21T16:54:00Z

Links: CVE-2024-10270 - Bugzilla