CVE-2023-6841
A denial of service vulnerability was found in keycloak where the amount of attributes per object is not limited,an attacker by sending repeated HTTP requests could cause a resource exhaustion when the application send back rows with long attribute values.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.61%
- CWE
- CWE-231
- Published
- 2024-09-10
- Last modified
- 2026-03-13
Weakness type
Related vulnerabilities
- CVE-2026-22888 — Improper input verification issue exists in Cybozu Garoon 5.0.0 to 6.0.3, which may lead to...
- CVE-2024-20268 — Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software SNMP Denial of Service Vulnerability
- CVE-2023-44386 — Incorrect request error handling triggers server crash in Vapor