CVE-2024-1249
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
- EPSS probability
- 0.45%
- CWE
- CWE-346
- Published
- 2024-04-17
- Last modified
- 2026-09-08
Affected products
- Red Hat Red Hat build of Keycloak 22
- Red Hat Red Hat build of Keycloak 22
- Red Hat Red Hat build of Keycloak 22
- Red Hat Red Hat Single Sign-On 7.6 for RHEL 7
- Red Hat Red Hat Single Sign-On 7.6 for RHEL 8
- Red Hat Red Hat Single Sign-On 7.6 for RHEL 9
- Red Hat RHEL-8 based Middleware Containers
- Red Hat RHOSS-1.33-RHEL-8
Weakness type
Related vulnerabilities
- CVE-2025-34291 — Langflow <= 1.6.9 CORS Misconfiguration to Token Hijack & RCE
- CVE-2026-54069 — SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist
- CVE-2025-9265 — API Authentication Bypass via Header Spoofing vulnerability in Kiloview NDI N30 Products
- CVE-2025-69258 — A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta
- CVE-2026-22794 — Account Takeover Vulnerability in Appsmith
- CVE-2025-59159 — SillyTavern Web Interface Vulnerable to DNS Rebinding
- CVE-2026-27478 — Unity Catalog has a JWT Issuer Validation Bypass Allows Complete User Impersonation
- CVE-2024-14006 — Nagios XI < 2024R1.2.2 Host Header Injection