CVE-2024-1249 - CVE House
Back to Database
Status published High CVE-2024-1249

Keycloak: org.keycloak.protocol.oidc: unvalidated cross-origin messages in checkloginiframe leads to ddos

Vulnerability Description

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-1249

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Adriano Márcio Monteiro for reporting this issue.

Affected Vendor

Affected Software

Red Hat AMQ Broker 7, Red Hat build of Keycloak 22, Red Hat build of Keycloak 22.0.10, Red Hat Single Sign-On 7.6 for RHEL 7, Red Hat Single Sign-On 7.6 for RHEL 8, Red Hat Single Sign-On 7.6 for RHEL 9, RHEL-8 based Middleware Containers, RHOSS-1.33-RHEL-8, RHSSO 7.6.8, Migration Toolkit for Applications 6, Migration Toolkit for Applications 7, Red Hat build of Apicurio Registry 2, Red Hat Data Grid 8, Red Hat Decision Manager 7, Red Hat Developer Hub, Red Hat Fuse 7, Red Hat JBoss Data Grid 7, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7, Red Hat JBoss Enterprise Application Platform 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat Process Automation 7, streams for Apache Kafka
Vulnerable Versions:
21.1.0, 23.0.0, 22.0.10-1, 22-13, 22-16, 0:18.0.13-1.redhat_00001.1.el7sso, 0:18.0.13-1.redhat_00001.1.el8sso, 0:18.0.13-1.redhat_00001.1.el9sso, 7.6-46, 1.33.0-5, 1.33.0-3

Timeline

Official Publish: April 17th, 2024
Last Modified: June 2nd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H

Weaknesses (CWE)