cbcvebase.
CVE-2023-6563
published 2023-12-14

CVE-2023-6563: An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (>…

PriorityP340high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
1.24%
65.8th percentile
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

Affected

8 ranges
VendorProductVersion rangeFixed in
redhatkeycloak< 21.0.021.0.0
redhatopenshift_container_platform
redhatopenshift_container_platform
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_ibm_linuxone
redhatopenshift_container_platform_for_power
redhatopenshift_container_platform_for_power
redhatsingle_sign-on

CVSS provenance

nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.