A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3389 | A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity. |
Github GHSA |
GHSA-wq8x-cg39-8mrr | org.keycloak:keycloak-services has Inefficient Regular Expression Complexity |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 25 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 25 Nov 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.keycloak:keycloak-services: Keycloak Denial of Service | Org.keycloak:keycloak-services: keycloak denial of service |
| First Time appeared |
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 |
|
| Vendors & Products |
Redhat jboss Enterprise Application Platform
Redhat jbosseapxp Redhat red Hat Single Sign On |
|
| References |
|
|
Fri, 22 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity. | |
| Title | org.keycloak:keycloak-services: Keycloak Denial of Service | |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| Weaknesses | CWE-1333 | |
| CPEs | cpe:/a:redhat:build_keycloak:24 cpe:/a:redhat:build_keycloak:24::el9 cpe:/a:redhat:build_keycloak:26 cpe:/a:redhat:build_keycloak:26.0::el9 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-11T16:08:34.510Z
Reserved: 2024-10-23T02:00:58.671Z
Link: CVE-2024-10270
Updated: 2024-11-25T17:15:04.831Z
Status : Received
Published: 2024-11-25T08:15:03.747
Modified: 2024-11-25T08:15:03.747
Link: CVE-2024-10270
OpenCVE Enrichment
No data.
EUVD
Github GHSA