CVE-2023-6563: Keycloak: offline session token dos

Published Dec 6, 2023
·
Updated

A vulnerability has been discovered in the way RH-SSO handles offline tokens, which can be exploited to cause a denial of service via memory exhaustion. The issue is caused by the way how the server processes offline tokens.

An attacker can exploit this vulnerability by creating just two offline tokens. Once these tokens are created, the attacker can interact with the endpoint by triggering a list of the multiple sessions of the user. In environments where there could be potentially millions of offline tokens created by all users, this action leads to an excessive consumption of server memory.

Other sources

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

Affected Software

17 affected componentsFixes available
maven/org.keycloak:keycloak-model-jpa<21.0.0
21.0.0
redhat/keycloak<21.0.0
21.0.0
redhat keycloak<21.0.0
All of the following
redhat Single Sign-on=7.6
Any of the following
redhat Enterprise Linux=7.0
redhat Enterprise Linux=8.0
redhat Enterprise Linux=9.0
redhat Single Sign-on
All of the following
Any of the following
redhat OpenShift Container Platform=4.11
redhat OpenShift Container Platform=4.12
redhat Enterprise Linux=8.0
All of the following
Any of the following
redhat Openshift Container Platform For Power=4.9
redhat Openshift Container Platform For Power=4.10
redhat Enterprise Linux=8.0
All of the following
Any of the following
redhat Openshift Container Platform For Ibm Linuxone=4.9
redhat Openshift Container Platform For Ibm Linuxone=4.10
redhat Enterprise Linux=8.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.keycloak:keycloak-model-jpa to a version that resolves this vulnerability.

    Fixed in 21.0.0
  2. Upgrade

    Upgrade redhat/keycloak to a version that resolves this vulnerability.

    Fixed in 21.0.0

Event History

Dec 14, 2023
CVE Published
06:01 PM
Data Sourced
06:01 PM
DescriptionSeverityWeakness
Advisory Published
06:30 PM

Frequently Asked Questions

1

What is the severity of CVE-2023-6563?

CVE-2023-6563 is classified as a high-severity vulnerability due to its potential for causing denial of service through memory exhaustion.

2

How do I fix CVE-2023-6563?

To mitigate CVE-2023-6563, upgrade to the fixed versions, specifically keycloak and keycloak-model-jpa at version 21.0.0 or higher.

3

What products are affected by CVE-2023-6563?

CVE-2023-6563 affects Red Hat Single Sign-On versions up to 7.6 and Keycloak versions up to 21.0.0.

4

Can CVE-2023-6563 be exploited remotely?

Yes, CVE-2023-6563 can be exploited remotely if an attacker sends crafted requests targeting offline tokens.

5

What impact does CVE-2023-6563 have on my system?

Exploitation of CVE-2023-6563 may lead to a denial of service, causing system instability and performance degradation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203