← voltar
CVE-2023-6841highCWE-231

Keycloak: amount of attributes per object is not limited and it may lead to dos

21Vexday Risk Score

Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.

ssvc Trackcvss 7.5epss 0.7%
probabilidade de exploração
0.7%top 49% das CVEs
exploração observada
nãonenhuma fonte reporta
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H