CVE-2024-1249
HIGHOrg.keycloak Keycloak-services < 22.0.10 - Origin Validation Error
Title source: ruleDescription
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
References (11)
Scores
CVSS v3
7.4
EPSS
0.0017
EPSS Percentile
38.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Classification
CWE
CWE-346
Status
draft
Affected Products (1)
org.keycloak/keycloak-services
< 22.0.10Maven
Timeline
Published
Apr 17, 2024
Tracked Since
Feb 18, 2026