CVE-2020-10758
16.09.2020, 16:15
A vulnerability was found in Keycloak before 11.0.1 where DoS attack is possible by sending twenty requests simultaneously to the specified keycloak server, all with a Content-Length header value that exceeds the actual byte count of the request body.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | keycloak | 𝑥 < 11.0.1 |
| redhat | openshift_application_runtimes | - |
| redhat | openshift_application_runtimes | 1.0 |
| redhat | single_sign-on | - |
| redhat | single_sign-on | 7.0 |
| redhat | single_sign-on | 7.4 |
𝑥
= Vulnerable software versions