CVE-2023-6841
HIGHDescription
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
Is your site exposed to CVE-2023-6841?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| redhat | keycloak |
| redhat | single_sign-on |
References
Frequently Asked Questions
What is CVE-2023-6841? +
How severe is CVE-2023-6841? +
What products are affected by CVE-2023-6841? +
How do I check if I'm vulnerable to CVE-2023-6841? +
Related Vulnerabilities
A vulnerability in the Simple Network Management Protocol (SNMP) feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower …
Improper handling of extra values issue exists in Cybozu Garoon 5.0.0 to 5.15.2. If this vulnerability is exploited, a user …
An authentication bypass vulnerability has been identified in Foreman when deployed with External Authentication, due to the puppet-foreman configuration. This …
An authentication bypass vulnerability has been identified in Pulpcore when deployed with Gunicorn versions prior to 22.0, due to the …
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button …
A heap-based buffer overflow flaw was found in the rsync daemon. This issue is due to improper handling of attacker-controlled …