CVE-2018-10912
published 2018-07-23CVE-2018-10912: keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired…
PriorityP420medium4.9CVSS 3.1
AVNACLPRHUINSUCNINAH
EPSS
1.31%
67.5th percentile
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 4.0.0 | 4.0.0 |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv3.04.4MEDIUMCVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: infinite loop in session replacement leading to denial of service
vendor_redhat·2018-05-25·CVSS 4.9
CVE-2018-10912 [MEDIUM] CWE-835 keycloak: infinite loop in session replacement leading to denial of service
keycloak: infinite loop in session replacement leading to denial of service
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
Package: keycloak (Red Hat Fuse 7) - Not affected
Package: keycloak (Red Hat Mobile Application Platform 4) - Not affected
Package: keycloak (Red Hat OpenShift Application Runtimes) - Affected
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Affected
OSV
Moderate severity vulnerability that affects org.keycloak:keycloak-core
osv·2018-10-18
CVE-2018-10912 [MEDIUM] Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
GHSA
Moderate severity vulnerability that affects org.keycloak:keycloak-core
ghsa·2018-10-18
CVE-2018-10912 [MEDIUM] CWE-835 Moderate severity vulnerability that affects org.keycloak:keycloak-core
Moderate severity vulnerability that affects org.keycloak:keycloak-core
keycloak before version 4.0.0.final is vulnerable to a infinite loop in session replacement. A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
bugzilla·2019-06-12·CVSS 5.3
CVE-2019-10909 [MEDIUM] CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
CVE-2019-10909 CVE-2019-10910 CVE-2019-10912 CVE-2019-10913 CVE-2018-19790 CVE-2018-19789 php-symfony: Multiple vulnerabilities fixed in symfony 2.8.7
Multiple vulnerabilities were discovered in the Symfony PHP framework
which could lead to cache bypass, authentication bypass, information
disclosure, open redirect, cross-site request forgery, deletion of
arbitrary files, or arbitrary code execution.
References:
https://www.debian.org/security/2019/dsa-4441
https://security-tracker.debian.org/tracker/symfony
Discussion:
Created php-symfony tracking bugs for this issue:
Affects: epel-all [bug 1719512]
Affects: fedora-all [bug 1719511]
Created php-symfony3 tracking bugs for this issue:
Affects: fedora-all [bug 1719513]
Created php-symfony4 tracking bugs for this issue:
Affects: fe
Bugzilla
CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service
bugzilla·2018-07-23·CVSS 4.9
CVE-2018-10912 [MEDIUM] CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service
CVE-2018-10912 keycloak: infinite loop in session replacement leading to denial of service
A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
Discussion:
This issue has been addressed in the following products:
Red Hat Single Sign-On 7.2.4 zip
Via RHSA-2018:2428 https://access.redhat.com/errata/RHSA-2018:2428
---
This issue has been addressed in the following products:
Red Hat Openshift Application Runtimes
Via RHSA-2019:0877 https://access.redhat.com/errata/RHSA-2019:0877
---
*** Bug 1582623 has been marked as a duplicate of this bug. ***
https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10912https://access.redhat.com/errata/RHSA-2018:2428https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-10912
2018-07-23
Published