Description

A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.

INFO

Published Date :

2024-09-10T16:15:32.639Z

Last Modified :

2025-11-08T07:10:39.283Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2023-6841 vulnerability.

Vendors Products
Redhat
  • Jboss Enterprise Bpms Platform
  • Jboss Fuse
  • Keycloak
  • Mobile Application Platform
  • Openshift Application Runtimes
  • Red Hat Single Sign On
  • Single Sign-on

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact