Red Hat Bugzilla – Bug 1582623
CVE-2018-10842 keycloak: denial of service via infinite loop in session management
Last modified: 2018-08-13 11:46:08 EDT
It was found that an authenticated user could manipulate user session information to trigger an infinite loop in keycloak. A malicious user could use this flaw to conduct a denial of service attack against the server.