CVE-2024-1249

Source
https://cve.org/CVERecord?id=CVE-2024-1249
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-1249.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-1249
Aliases
Downstream
Related
Published
2024-04-17T13:22:48.335Z
Modified
2026-05-18T05:58:45.703316014Z
Severity
  • 7.4 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos
Details

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Database specific
{
    "cna_assigner": "redhat",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/1xxx/CVE-2024-1249.json",
    "cwe_ids": [
        "CWE-346"
    ]
}
References

Affected packages

Git / github.com/keycloak/keycloak

Affected ranges

Type
GIT
Repo
https://github.com/keycloak/keycloak
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "21.1.0"
        },
        {
            "fixed": "22.0.10"
        },
        {
            "introduced": "23.0.0"
        },
        {
            "fixed": "24.0.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-1249.json"