CVE-2018-10912: Medium severity red hat keycloak vulnerability
Published Jul 23, 2018
·Updated
A Keycloak cluster with multiple nodes could mishandle an expired session replacement and lead to an infinite loop. A malicious authenticated user could use this flaw to achieve Denial of Service on the server.
Affected Software
3 affected componentsFixes available
redhat/Keycloak<4.0.0.
4.0.0.
redhat keycloak<4.0.0
redhat Single Sign-on=7.2
Event History
Jul 23, 2018
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-10912?
CVE-2018-10912 is rated as a high severity vulnerability due to its potential to cause Denial of Service in Keycloak environments.
2
How do I fix CVE-2018-10912?
To mitigate CVE-2018-10912, upgrade Keycloak to version 4.0.0 or later.
3
Who is affected by CVE-2018-10912?
CVE-2018-10912 affects users of Keycloak versions prior to 4.0.0, particularly in clustered environments.
4
What are the consequences of CVE-2018-10912?
Exploiting CVE-2018-10912 can lead to an infinite loop situation causing Denial of Service for Keycloak instances.
5
Is a patch available for CVE-2018-10912?
Yes, a patch is available through the official upgrade to Keycloak version 4.0.0 and above.