REDHAT-BUG-2482473: Medium severity Red Hat Keycloak vulnerability
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromising an upstream LDAP server, could exploit this vulnerability. By sending a malformed LDAP password policy response during a password authentication request, the attacker can trigger an OutOfMemoryError. This causes the Keycloak Java Virtual Machine (JVM) to terminate, leading to a denial of service (DoS) for all realms on the affected node.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2482473?
The severity of REDHAT-BUG-2482473 is classified as medium with a score of 4.
What does the vulnerability REDHAT-BUG-2482473 affect?
REDHAT-BUG-2482473 affects the Red Hat Keycloak software.
How can an attacker exploit REDHAT-BUG-2482473?
An attacker can exploit REDHAT-BUG-2482473 by configuring a malicious LDAP server or compromising an upstream LDAP server to send a malformed LDAP password.
Who is at risk from REDHAT-BUG-2482473?
A remote attacker with high privileges, such as a realm administrator, is at risk from REDHAT-BUG-2482473.
What should I do to mitigate the risks of REDHAT-BUG-2482473?
To mitigate the risks of REDHAT-BUG-2482473, ensure that your LDAP configuration is secure and validate all LDAP inputs carefully.