Skip to main content

Origin Validation Error

CVE-2024-1249

Severity High
Score 7.4/10

Summary

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages. This issue affects the package org.keycloak:keycloak-services versions through 22.0.9, and 23.0.0 through 24.0.2.

  • LOW
  • NETWORK
  • NONE
  • CHANGED
  • REQUIRED
  • NONE
  • NONE
  • HIGH

CWE-346 - Origin Validation Error

The software does not properly verify that the source of data or communication is valid.

Advisory Timeline

  • Published