CVE-2014-3651
HIGHKeycloak < 1.0.3 - Denial of Service via Large QR Code Size Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-3651. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary This repository contains source code for Keycloak, specifically focusing on JPA and MongoDB connection providers. It includes vulnerable code related to CVE-2014-3651 but does not provide an exploit PoC or detailed analysis of the vulnerability.
Description
JBoss KeyCloak before 1.0.3.Final allows remote attackers to cause a denial of service (resource consumption) via a large value in the size parameter to auth/qrcode, related to QR code generation.
Exploits (2)
This repository contains source code for Keycloak, specifically focusing on JPA and MongoDB connection providers. It includes vulnerable code related to CVE-2014-3651 but does not provide an exploit PoC or detailed analysis of the vulnerability.
This repository contains source code for Keycloak, specifically focusing on JPA and MongoDB connection providers. It appears to be a snapshot of vulnerable code related to CVE-2014-3651, but lacks exploit code or detailed analysis of the vulnerability itself.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H