GHSA-pcx7-8hxg-j823

Suggest an improvement
Source
https://github.com/advisories/GHSA-pcx7-8hxg-j823
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-pcx7-8hxg-j823/GHSA-pcx7-8hxg-j823.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pcx7-8hxg-j823
Withdrawn
2024-11-25T19:35:56Z
Published
2024-11-25T09:30:59Z
Modified
2024-12-06T05:29:49Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Duplicate Advisory: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-jgwc-jh89-rpgq. This link is maintained to preserve external references.

Original Description

A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.

Database specific
{
    "cwe_ids":  [
        "CWE-444"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-11-25T19:35:56Z",
    "nvd_published_at":  "2024-11-25T08:15:10Z",
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
View open source insights on deps.dev
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.0.9

Affected versions

12.*
12.0.0
12.0.1
12.0.2
12.0.3
12.0.4
13.*
13.0.0
13.0.1
14.*
14.0.0
15.*
15.0.0
15.0.1
15.0.2
15.1.0
15.1.1
16.*
16.0.0
16.1.0
16.1.1
17.*
17.0.0
17.0.1
18.*
18.0.0
18.0.1
18.0.2
19.*
19.0.0
19.0.1
19.0.2
19.0.3
20.*
20.0.0
20.0.1
20.0.2
20.0.3
20.0.4
20.0.5
21.*
21.0.0
21.0.1
21.0.2
21.1.0
21.1.1
21.1.2
22.*
22.0.0
22.0.1
22.0.2
22.0.3
22.0.4
22.0.5
23.*
23.0.0
23.0.1
23.0.2
23.0.3
23.0.4
23.0.5
23.0.6
23.0.7
24.*
24.0.0
24.0.1
24.0.2
24.0.3
24.0.4
24.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-pcx7-8hxg-j823/GHSA-pcx7-8hxg-j823.json"

Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
View open source insights on deps.dev
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
25.0.0
Fixed
26.0.6

Affected versions

25.*
25.0.0
25.0.1
25.0.2
25.0.3
25.0.4
25.0.5
25.0.6
26.*
26.0.0
26.0.1
26.0.2
26.0.4
26.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-pcx7-8hxg-j823/GHSA-pcx7-8hxg-j823.json"