Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-6563
HistoryDec 14, 2023 - 6:15 p.m.

Memory corruption

2023-12-1418:15:00
PRIOn knowledge base
www.prio-n.com
8
keycloak
memory corruption
vulnerability
offline tokens
user sessions
admin ui
excessive memory
cpu consumption

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

39.4%

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the “consents” tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

39.4%