A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Jun 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
|
Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
|
References |
|
Tue, 17 Sep 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-06-25T00:32:06.355Z
Reserved: 2024-02-06T06:20:24.574Z
Link: CVE-2024-1249

Updated: 2024-08-01T18:33:25.533Z

Status : Awaiting Analysis
Published: 2024-04-17T14:15:08.160
Modified: 2025-06-25T01:15:22.707
Link: CVE-2024-1249
