CVE-2024-1249

HIGH

Org.keycloak Keycloak-services < 22.0.10 - Origin Validation Error

Title source: rule

Description

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Scores

CVSS v3 7.4
EPSS 0.0017
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

Classification

CWE
CWE-346
Status draft

Affected Products (1)

org.keycloak/keycloak-services < 22.0.10Maven

Timeline

Published Apr 17, 2024
Tracked Since Feb 18, 2026