CVE-2024-1249
Keycloak's unvalidated cross-origin messages in checkLoginIframe leads to DDoS
7.4
HIGH
CVSS 3.1
EPSS 0.23%
Description
A potential security flaw in the "checkLoginIframe" which allows unvalidated cross-origin messages, enabling potential DDoS attacks. By exploiting this vulnerability, attackers could coordinate to send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages. #### Acknowledgements Special thanks to Adriano Márcio Monteiro from BRZTEC for reporting this issue and helping us improve our project.
How to fix CVE-2024-1249
To remediate CVE-2024-1249, upgrade the affected package to a fixed version below.
- —upgrade to 22.0.10 or later
Is CVE-2024-1249 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 22.0.10
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.4 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H |