CVE-2024-1249
Red Hat Red Hat AMQ Broker 7, Red Hat build of Keycloak 22, Red Hat build of Keycloak 22.0.10
A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.
- CVSS
- 7.4
- EPSS
- 0.45% 36.7% percentile
- CISA KEV
- Not listed
- Published
- 2024.04.17