CVE-2023-6563
published 2023-12-14CVE-2023-6563: An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (>…
PriorityP340high7.7CVSS 3.1
AVNACLPRLUINSCCNINAH
EPSS
1.24%
65.8th percentile
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 21.0.0 | 21.0.0 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_ibm_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.17.7HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Allocation of Resources Without Limits in Keycloak
ghsa·2023-12-14
CVE-2023-6563 [HIGH] CWE-770 Allocation of Resources Without Limits in Keycloak
Allocation of Resources Without Limits in Keycloak
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
OSV
Allocation of Resources Without Limits in Keycloak
osv·2023-12-14
CVE-2023-6563 [HIGH] Allocation of Resources Without Limits in Keycloak
Allocation of Resources Without Limits in Keycloak
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
Red Hat
keycloak: offline session token DoS
vendor_redhat·2023-12-14·CVSS 7.7
CVE-2023-6563 [HIGH] CWE-770 keycloak: offline session token DoS
keycloak: offline session token DoS
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then ope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:7854https://access.redhat.com/errata/RHSA-2023:7855https://access.redhat.com/errata/RHSA-2023:7856https://access.redhat.com/errata/RHSA-2023:7857https://access.redhat.com/errata/RHSA-2023:7858https://access.redhat.com/security/cve/CVE-2023-6563https://bugzilla.redhat.com/show_bug.cgi?id=2253308https://github.com/keycloak/keycloak/issues/13340https://access.redhat.com/errata/RHSA-2023:7854https://access.redhat.com/errata/RHSA-2023:7855https://access.redhat.com/errata/RHSA-2023:7856https://access.redhat.com/errata/RHSA-2023:7857https://access.redhat.com/errata/RHSA-2023:7858https://access.redhat.com/security/cve/CVE-2023-6563https://bugzilla.redhat.com/show_bug.cgi?id=2253308https://github.com/keycloak/keycloak/issues/13340
2023-12-14
Published