HIGH
keycloak: DoS via SAML request
Published Jul 27, 2018
7.5
HIGHCVSS 3.0
EPSS 1.83%
Description
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.
Affected products
-
- Version 2.5.5StatusaffectedConstraints-
- Version
No data.
Red Hat Single Sign-On 7
rh-sso7-keycloak
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://www.securityfocus.com/bid/96882 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-2646 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1431230 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2646 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/advisories/GHSA-jc6q-27mw-p55w Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-2646
- https://www.cve.org/CVERecord?id=CVE-2017-2646
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/96882 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-2646 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1431230 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2646 | x_refsource_CONFIRMIssue TrackingThird Party Advisory | |
| https://github.com/advisories/GHSA-jc6q-27mw-p55w | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-2646 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-2646 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jul 27, 2018
Updated Aug 5, 2024
Reserved Dec 1, 2016
Link CVE-2017-2646
CISA Vulnrichment
GHSA-JC6Q-27MW-P55W Updated n/a