CVE-2020-10758
published 2020-09-16CVE-2020-10758: A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.24%
80.9th percentile
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 11.0.1 | 11.0.1 |
| redhat | keycloak | — | — |
| redhat | openshift_application_runtimes | — | — |
| redhat | single_sign-on | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Allocation of Resources Without Limits or Throttling in Keycloak
osv·2022-02-09
CVE-2020-10758 [HIGH] Allocation of Resources Without Limits or Throttling in Keycloak
Allocation of Resources Without Limits or Throttling in Keycloak
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
GHSA
Allocation of Resources Without Limits or Throttling in Keycloak
ghsa·2022-02-09
CVE-2020-10758 [HIGH] CWE-770 Allocation of Resources Without Limits or Throttling in Keycloak
Allocation of Resources Without Limits or Throttling in Keycloak
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
Red Hat
keycloak: DoS by sending multiple simultaneous requests with a Content-Length header value greater than actual byte count of request body
vendor_redhat·2020-08-18·CVSS 7.5
CVE-2020-10758 [HIGH] CWE-400 keycloak: DoS by sending multiple simultaneous requests with a Content-Length header value greater than actual byte count of request body
keycloak: DoS by sending multiple simultaneous requests with a Content-Length header value greater than actual byte count of request body
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.
A flaw was found in Keycloak. This flaw allows an attacker to perform a denial of service attack by sending multiple simultaneous requests with a Content-Length header value greater than the actual byte count of the request body. The highest threat from this vulnerability is to system availability.
Mitigation: - The possibility of this issue largely depends on the environment, specifically the load balan
No detection rules found.
No public exploits indexed.
2020-09-16
Published