Red Hat Bugzilla – Bug 1607624
CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service
Last modified: 2018-09-19 17:14:10 EDT
A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
This issue has been addressed in the following products: Red Hat Single Sign-On 7.2.4 zip Via RHSA-2018:2428 https://access.redhat.com/errata/RHSA-2018:2428