Bug 2321214 (CVE-2024-10270)
| Summary: | CVE-2024-10270 org.keycloak:keycloak-services: Keycloak Denial of Service | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | alicesphere583, annakylie0902, asoldano, bbaranow, blessingmaseko1, bmaxwell, boliveir, brian.stansberry, btom66245, chazlett, connexionguide, darran.lofthouse, dkreling, dosoudil, drichtar, egg1538419, evelynwang0308, giuseppe.rinaldi876, istudens, ivassile, iweiss, jkoops, jobsplaces654, johnlarrylike, johnnyfeng2022, kaylafannin042, mosmerov, msochure, msvehla, nwallace, pdrozd, peholase, pesilva, pjindal, pmackay, pskopek, rmartinc, rowaters, rstancel, Sanaaliage2000, security-response-team, smaestri, sthorger, techszip24, tom.jenkinson |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Deadline: | 2024-11-21 | ||
|
Description
OSIDB Bzimport
2024-10-23 01:55:08 UTC
This issue has been addressed in the following products: Red Hat build of Keycloak 24 Via RHSA-2024:10175 https://access.redhat.com/errata/RHSA-2024:10175 This issue has been addressed in the following products: Red Hat build of Keycloak 24.0.9 Via RHSA-2024:10176 https://access.redhat.com/errata/RHSA-2024:10176 This issue has been addressed in the following products: Red Hat build of Keycloak 26.0 Via RHSA-2024:10177 https://access.redhat.com/errata/RHSA-2024:10177 This issue has been addressed in the following products: Red Hat build of Keycloak 26.0.6 Via RHSA-2024:10178 https://access.redhat.com/errata/RHSA-2024:10178 (In reply to errata-xmlrpc from comment #3) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0 > > Via RHSA-2024:10177 https://slope3.com https://access.redhat.com/errata/RHSA-2024:10177 Link ID: Red Hat Product Errata RHSA-2024:10177 upstream commit: https://github.com/keycloak/keycloak/commit/5d6c91f3309db468b0fe4834e88c3d25649f73e4 (In reply to errata-xmlrpc from comment #4) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0.6 > > Via RHSA-2024:10178 https://grade-calculator.io/ https://access.redhat.com/errata/RHSA-2024:10178 Link ID: Red Hat Product Errata RHSA-2024:10178 (In reply to errata-xmlrpc from comment #5) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0.6 > > Via RHSA-2024:10178 https://doodlejump24.io/ https://access.redhat.com/errata/RHSA-2024:10178 Link ID: Red Hat Product Errata RHSA-2024:10178 I really value all the work you've put into this. Thanks for giving us such useful information. This issue has been addressed in the following products:
>
> Red Hat build of Keycloak 26.0.6
>
> Via RHSA-2024:10178 https://cargamesonline.io/ https://access.redhat.com/errata/RHSA-2024:10178
I sincerely appreciate all of your hard work on this. We appreciate you providing us with this helpful information.
(In reply to errata-xmlrpc from comment #4) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0.6 > > Via RHSA-2024:10178 https://wheelielife.io/ https://access.redhat.com/errata/RHSA-2024:10178 Link ID: Red Hat Product Errata RHSA-2024:10176 Thanks for sharing this important security update about Keycloak vulnerabilities. It's crucial to stay informed about these issues. Speaking of helpful resources, when I need gaming help, I always check out the https://www.pixel-flow-level.com for great puzzle solutions. Thanks for sharing this important security update about Keycloak vulnerabilities. It's crucial to stay informed about these issues. Speaking of helpful resources, when I need gaming help, I always check out the https://www.pixel-flow-level.com for great puzzle solutions. Thanks for the detailed update and references. It’s good to see this Keycloak issue has been properly addressed across supported versions via official Red Hat advisories. Staying on top of security fixes like this is critical. For anyone also dealing with time tracking or work-hour calculations alongside system administration tasks, https://calcoloorelavorative.it/ can be quite useful in day-to-day workflows. Thank you for sharing. https://connectionssolver.com/nyt-capture-solver-answers Brand engagement increases once Press Release Distribution highlights corporate achievements. Readers feel confident.https://kingnewswire.com/ Beginner woodworking for carpentry https://www.woodwork-for-beginners.com worm farming composting https://wormfarmingforbeginners.com beekeeping honey bees https://beekeeping-for-beginner.com animals on livestock farming https://www.guidetoprofitablelivestock.com This security update sounds important. By the way, I've been playing toontone game (https://toon-tone.com/character-color-game/) to relax between patches. It's a fun color memory challenge! Thanks for reporting and tracking this issue. Clear bug reports and community feedback are essential for improving open-source software, and discussions like this help developers identify and resolve problems more efficiently. For a quick break between debugging sessions, <a href="https://motox3m3.io">Moto X3M</a> is a fun browser game to check out. Thanks for reporting and tracking this issue. Detailed bug reports like this really help developers identify, reproduce, and resolve problems more efficiently. It's great to see the discussion include useful technical details and testing results. While troubleshooting or verifying values during debugging, I sometimes use https://calcsolver.me for quick calculations. Hopefully this gets resolved in a future update. This issue has been addressed in the following products:
>
> Red Hat build of Keycloak 26.0.6
>
> Via RHSA-2024:10178 https://chick-fil-a-menu.one/ https://access.redhat.com/errata/RHSA-2024:10178
Link ID: Red Hat Product Errata RHSA-2024:10178
|