vulnerability

FreeBSD: VID-5E2BD238-D2BB-11EF-BC0E-1C697A616631 (CVE-2024-11734): keycloak -- Multiple security fixes

Severity
7
CVSS
(AV:N/AC:L/Au:S/C:N/I:N/A:C)
Published
2025-01-13
Added
2025-01-16
Modified
2025-01-28

Description

A denial of service vulnerability was found in Keycloak that could allow an administrative user with the right to change realm settings to disrupt the service. This action is done by modifying any of the security headers and inserting newlines, which causes the Keycloak server to write to a request that has already been terminated, leading to the failure of said request.

Solution

freebsd-upgrade-package-keycloak
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.