vulnerability
FreeBSD: VID-5E2BD238-D2BB-11EF-BC0E-1C697A616631 (CVE-2024-11734): keycloak -- Multiple security fixes
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:S/C:N/I:N/A:C) | 2025-01-13 | 2025-01-16 | 2025-01-28 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:C)
Published
2025-01-13
Added
2025-01-16
Modified
2025-01-28
Description
A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.
Solution
freebsd-upgrade-package-keycloak
References

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.