cbcvebase.
CVE-2020-10758
published 2020-09-16

CVE-2020-10758: A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.

Affected

5 ranges
VendorProductVersion rangeFixed in
redhatkeycloak< 11.0.111.0.1
redhatkeycloak
redhatopenshift_application_runtimes
redhatsingle_sign-on
redhatsingle_sign-on