2024-04-17 16:03:28 +00:00
{
"id" : "CVE-2024-1249" ,
"sourceIdentifier" : "secalert@redhat.com" ,
"published" : "2024-04-17T14:15:08.160" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T08:50:09.153" ,
2024-04-17 16:03:28 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-04-17 16:03:28 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "A flaw was found in Keycloak's OIDC component in the \"checkLoginIframe,\" which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages."
2024-04-21 02:03:21 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se encontr\u00f3 una falla en el componente OIDC de Keycloak en \"checkLoginIframe\", que permite mensajes de origen cruzado no validados. Esta falla permite a los atacantes coordinar y enviar millones de solicitudes en segundos usando un c\u00f3digo simple, lo que afecta significativamente la disponibilidad de la aplicaci\u00f3n sin una validaci\u00f3n adecuada del origen de los mensajes entrantes."
2024-04-17 16:03:28 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "secalert@redhat.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.4 ,
"baseSeverity" : "HIGH" ,
2024-04-17 16:03:28 +00:00
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "CHANGED" ,
"confidentialityImpact" : "NONE" ,
"integrityImpact" : "NONE" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-04-17 16:03:28 +00:00
} ,
"exploitabilityScore" : 2.8 ,
"impactScore" : 4.0
}
]
} ,
"weaknesses" : [
{
"source" : "secalert@redhat.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-346"
}
]
}
] ,
"references" : [
2024-04-17 18:03:28 +00:00
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1860" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1861" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1862" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1864" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1866" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1867" ,
"source" : "secalert@redhat.com"
} ,
2024-04-17 16:03:28 +00:00
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1868" ,
"source" : "secalert@redhat.com"
} ,
2024-05-21 20:03:32 +00:00
{
"url" : "https://access.redhat.com/errata/RHSA-2024:2945" ,
"source" : "secalert@redhat.com"
} ,
2024-06-24 08:03:15 +00:00
{
"url" : "https://access.redhat.com/errata/RHSA-2024:4057" ,
"source" : "secalert@redhat.com"
} ,
2024-04-17 16:03:28 +00:00
{
"url" : "https://access.redhat.com/security/cve/CVE-2024-1249" ,
"source" : "secalert@redhat.com"
} ,
{
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2262918" ,
"source" : "secalert@redhat.com"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1860" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1861" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1862" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1864" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1866" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1867" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:1868" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:2945" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/errata/RHSA-2024:4057" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://access.redhat.com/security/cve/CVE-2024-1249" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2262918" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-04-17 16:03:28 +00:00
}
]
}