THREATOPS
THREAT OPSThreat News › [NVD] CVE-2023-6563 (HIGH 7.7) — An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the

[NVD] CVE-2023-6563 (HIGH 7.7) — An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the

lownvdPublished 2023-12-14

CVE-2023-6563 CVSS: 7.7 HIGH Published: 2023-12-14T18:15:45.540

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI att

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2023-6563