An unconstrained memory consumption... CVE-2023-6563

- AV AC AU C I A
发布: 2023-12-14
修订: 2023-12-27

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

0%
暂无可用Exp或PoC
当前有12条受影响产品信息