cbcvebase.
CVE-2021-3637
published 2021-07-09

CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.

Affected

2 ranges
VendorProductVersion rangeFixed in
redhatkeycloak< 14.0.014.0.0
redhatsingle_sign-on