7.7
CVSSv3

CVE-2023-6563

Published: 14/12/2023 Updated: 27/12/2023
CVSS v3 Base Score: 7.7 | Impact Score: 4 | Exploitability Score: 3.1
VMScore: 0

Vulnerability Summary

An unconstrained memory consumption vulnerability exists in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat keycloak

redhat single_sign-on 7.6

redhat single sign-on -

redhat openshift_container_platform 4.11

redhat openshift_container_platform 4.12

redhat openshift_container_platform_for_power 4.9

redhat openshift_container_platform_for_power 4.10

redhat openshift_container_platform_for_ibm_linuxone 4.9

redhat openshift_container_platform_for_ibm_linuxone 4.10

Vendor Advisories

Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 7 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 7Red Hat ...
Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 9 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 9Red Hat ...
Synopsis Important: Red Hat Single Sign-On 766 security update on RHEL 8 Type/Severity Security Advisory: Important Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic New Red Hat Single Sign-On 766 packages are now available for Red Hat Enterprise Linux 8Red Hat ...
Synopsis Important: Red Hat Single Sign-On 766 for OpenShift image enhancement and security update Type/Severity Security Advisory: Important Topic A new image is available for Red Hat Single Sign-On 766, running on OpenShift Container Platform 310 and 311, and 43Red Hat Product Security has rated this update as having a security impa ...
Synopsis Important: Red Hat Single Sign-On 766 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 76 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base ...
Description<!---->An unconstrained memory consumption vulnerability was discovered in Keycloak It can be triggered in environments which have millions of offline tokens (&gt; 500,000 users with each having at least 2 saved sessions) If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the ...