CVE-2021-3637
published 2021-07-09CVE-2021-3637: A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows…
high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 14.0.0 | 14.0.0 |
| redhat | single_sign-on | — | — |