GHSA-54f3-c6hg-865h
HIGHCVE-2023-6563An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to
- Affected
- < 21.0.0
- Fixed in
- 21.0.0
- Weakness
- CWE-770
- Published
- 2023-12-14
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereferencereferencereference