Origin Validation Error
CVE-2024-1249
Summary
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages. This issue affects the package org.keycloak:keycloak-services versions through 22.0.9, and 23.0.0 through 24.0.2.
- LOW
- NETWORK
- NONE
- CHANGED
- REQUIRED
- NONE
- NONE
- HIGH
CWE-346 - Origin Validation Error
The software does not properly verify that the source of data or communication is valid.
References
Advisory Timeline
- Published