THREAT OPS › Threat News › [NVD] CVE-2023-6563 (HIGH 7.7) — An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the
[NVD] CVE-2023-6563 (HIGH 7.7) — An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the
CVE-2023-6563 CVSS: 7.7 HIGH Published: 2023-12-14T18:15:45.540
An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI att
Indicators of compromise
- CVE-2023-6563cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-6563