Lucene search

K
osvGoogleOSV:GHSA-M6Q9-P373-G5Q8
HistoryApr 17, 2024 - 6:24 p.m.

Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS

2024-04-1718:24:38
Google
osv.dev
11
keycloak
cross-origin messages
checkloginiframe
ddos
security flaw
vulnerability
origin validation
adriano mΓ‘rcio monteiro
brztec
application security

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.0%

A potential security flaw in the β€œcheckLoginIframe” which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application’s availability without proper origin validation for incoming messages.

Acknowledgements

Special thanks to Adriano MΓ‘rcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.

7.4 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

13.0%