REDHAT-BUG-1144278: Low severity JBoss Keycloak vulnerability
It was discovered that by requesting a large enough image size for a generated QR code, a remote attacker could cause uncontrolled resource consumption leading to denial of service for legitimate users.
Upstream Issue:
https://issues.jboss.org/browse/KEYCLOAK-699
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1144278?
The severity of REDHAT-BUG-1144278 is classified as high due to its potential to cause denial of service.
How do I fix REDHAT-BUG-1144278?
To fix REDHAT-BUG-1144278, implement limits on the size of QR code images generated by your application.
Who is affected by REDHAT-BUG-1144278?
REDHAT-BUG-1144278 primarily affects users of JBoss Keycloak who utilize QR code generation features.
What is the impact of REDHAT-BUG-1144278?
The impact of REDHAT-BUG-1144278 is that it can lead to uncontrolled resource consumption, blocking legitimate users from accessing services.
Is there a workaround for REDHAT-BUG-1144278?
A potential workaround for REDHAT-BUG-1144278 is to monitor and restrict the size of incoming requests for QR code generation.