Org.keycloak/keycloak-quarkus-server: keycloak proxy header handling denial-of-service (dos) vulnerability
Published Nov 25, 2024
5.7
MEDIUMCVSS 4.0
EPSS 0.40%
Description
A vulnerability was found in the Keycloak Server. The Keycloak Server is vulnerable to a denial of service (DoS) attack due to improper handling of proxy headers. When Keycloak is configured to accept incoming proxy headers, it may accept non-IP values, such as obfuscated identifiers, without proper validation. This issue can lead to costly DNS resolution operations, which an attacker could exploit to tie up IO threads and potentially cause a denial of service. The attacker must have access to send requests to a Keycloak instance that is configured to accept proxy headers, specifically when reverse proxies do not overwrite incoming headers, and Keycloak is configured to trust these headers.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Build of Keycloak | affected |
|
No data.
No data.
Red Hat build of Keycloak 24
rhbk/keycloak-operator-bundle:24.0.9-1
Fixed · RHSA-2024:10175
Red Hat build of Keycloak 24
rhbk/keycloak-rhel9-operator:24-18
Fixed · RHSA-2024:10175
Red Hat build of Keycloak 24
rhbk/keycloak-rhel9:24-18
Fixed · RHSA-2024:10175
Red Hat build of Keycloak 24.0.9
n/a
Fixed · RHSA-2024:10176
Red Hat build of Keycloak 26.0
rhbk/keycloak-operator-bundle:26.0.6-2
Fixed · RHSA-2024:10177
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9-operator:26.0-6
Fixed · RHSA-2024:10177
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9:26.0-5
Fixed · RHSA-2024:10177
Red Hat build of Keycloak 26.0.6
n/a
Fixed · RHSA-2024:10178
Red Hat Build of Keycloak
keycloak-quarkus-server
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
keycloak-quarkus-server
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Keycloak 24 | rhbk/keycloak-operator-bundle:24.0.9-1 | Fixed | RHSA-2024:10175 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9-operator:24-18 | Fixed | RHSA-2024:10175 |
| Red Hat build of Keycloak 24 | rhbk/keycloak-rhel9:24-18 | Fixed | RHSA-2024:10175 |
| Red Hat build of Keycloak 24.0.9 | n/a | Fixed | RHSA-2024:10176 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-operator-bundle:26.0.6-2 | Fixed | RHSA-2024:10177 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9-operator:26.0-6 | Fixed | RHSA-2024:10177 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9:26.0-5 | Fixed | RHSA-2024:10177 |
| Red Hat build of Keycloak 26.0.6 | n/a | Fixed | RHSA-2024:10178 |
| Red Hat Build of Keycloak | keycloak-quarkus-server | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | keycloak-quarkus-server | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Enterprise Application Server 8 does not ship the affected component and so is not affected by this flaw.
References (11)
- https://access.redhat.com/errata/RHSA-2024:10175 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:10176 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:10177 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:10178 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2024-9666 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2317440 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-jgwc-jh89-rpgq Advisory
- https://github.com/keycloak/keycloak/issues/35216
- https://github.com/keycloak/keycloak/security/advisories/GHSA-jgwc-jh89-rpgq
- https://nvd.nist.gov/vuln/detail/CVE-2024-9666
- https://www.cve.org/CVERecord?id=CVE-2024-9666
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:10175 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:10176 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:10177 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:10178 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2024-9666 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2317440 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-jgwc-jh89-rpgq | Advisory | |
| https://github.com/keycloak/keycloak/issues/35216 | ||
| https://github.com/keycloak/keycloak/security/advisories/GHSA-jgwc-jh89-rpgq | ||
| https://nvd.nist.gov/vuln/detail/CVE-2024-9666 | ||
| https://www.cve.org/CVERecord?id=CVE-2024-9666 |
Change history (0)
No recorded changes yet.