A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
The product does not handle or incorrectly handles when more values are provided than expected.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Keycloak | Redhat | - (including) | - (including) |
| Single_sign-on | Redhat | 7.0 (including) | 7.0 (including) |