CVE-2021-3637: High severity redhat keycloak vulnerability
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
Other sources
A flaw was found in keycloak-model-infinispan where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
https://issues.redhat.com/browse/KEYCLOAK-16616
— Red Hat
A flaw was found in keycloak-model-infinispan where the authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly. This issue leads to a denial of service.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:9.0.15-1.redhat_00002.1.el6 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:9.0.15-1.redhat_00002.1.el7 - Upgrade
Upgrade
redhat/rh-sso7-keycloakto a version that resolves this vulnerability.Fixed in 0:9.0.15-1.redhat_00002.1.el8 - Upgrade
Upgrade
redhat/keycloakto a version that resolves this vulnerability.Fixed in 14.0.0 - Upgrade
Upgrade
keycloak-model-infinispanto a version that resolves this vulnerability.Fixed in 14.0.0 - Compensating control
Mitigate potential DoS impact by limiting/monitoring traffic to Keycloak endpoints handling authentication sessions until the fixed version is deployed.
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3637?
CVE-2021-3637 is a vulnerability found in keycloak-model-infinispan where the authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly, leading to a DoS attack.
Which versions of Keycloak are affected by CVE-2021-3637?
Keycloak versions before 14.0.0 are affected by CVE-2021-3637.
What is the severity of CVE-2021-3637?
CVE-2021-3637 has a severity level of high (7 out of 10).
How can I fix CVE-2021-3637?
To fix CVE-2021-3637, update Keycloak to version 14.0.0 or later.
Where can I find more information about CVE-2021-3637?
You can find more information about CVE-2021-3637 at the following references: [KEYCLOAK-16616](https://issues.redhat.com/browse/KEYCLOAK-16616), [RHSA-2021:3528](https://access.redhat.com/errata/RHSA-2021:3528), [RHSA-2021:3529](https://access.redhat.com/errata/RHSA-2021:3529).