CVE-2020-10758
16.09.2020, 16:15
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | keycloak | 𝑥 < 11.0.1 |
redhat | openshift_application_runtimes | - |
redhat | openshift_application_runtimes | 1.0 |
redhat | single_sign-on | - |
redhat | single_sign-on | 7.0 |
redhat | single_sign-on | 7.4 |
𝑥
= Vulnerable software versions