Asymmetric denial of service In org.keycloak:keycloak-parent
Description
Allocation of Resources Without Limits or Throttling in Keycloak A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 11.0.1 | ||
maven | 11.0.1 |
Aliases
1. 2. 3. 4.
References
1. 2.