A vulnerability was found in Keycloak-services package. If untrusted data is passed to the method (SearchQueryUtils), it could lead to a denial-of-service scenario by exhausting system resources.
This issue has been addressed in the following products: Red Hat build of Keycloak 24 Via RHSA-2024:10175 https://access.redhat.com/errata/RHSA-2024:10175
This issue has been addressed in the following products: Red Hat build of Keycloak 24.0.9 Via RHSA-2024:10176 https://access.redhat.com/errata/RHSA-2024:10176
This issue has been addressed in the following products: Red Hat build of Keycloak 26.0 Via RHSA-2024:10177 https://access.redhat.com/errata/RHSA-2024:10177
This issue has been addressed in the following products: Red Hat build of Keycloak 26.0.6 Via RHSA-2024:10178 https://access.redhat.com/errata/RHSA-2024:10178
(In reply to errata-xmlrpc from comment #3) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0 > > Via RHSA-2024:10177 https://slope3.com https://access.redhat.com/errata/RHSA-2024:10177 Link ID: Red Hat Product Errata RHSA-2024:10177
upstream commit: https://github.com/keycloak/keycloak/commit/5d6c91f3309db468b0fe4834e88c3d25649f73e4
(In reply to errata-xmlrpc from comment #4) > This issue has been addressed in the following products: > > Red Hat build of Keycloak 26.0.6 > > Via RHSA-2024:10178 https://grade-calculator.io/ https://access.redhat.com/errata/RHSA-2024:10178 Link ID: Red Hat Product Errata RHSA-2024:10178