-
Notifications
You must be signed in to change notification settings - Fork 7.9k
Labels
area/dist/quarkuskind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedteam/cloud-native
Milestone
Description
Before reporting an issue
- I have searched existing issues
- I have reproduced the issue with the latest nightly release
Area
dist/quarkus
Describe the bug
CVE-2023-44487 - HTTP/2 Rapid Reset Attack. Vulnerability in HTTP/2 protocol which allows relatively easy organize Denial Of Service attack.
netty-codec-http2 4.1.94 package included into Keycloak 22.0.4 is vulnerable. Fixed in netty-codec-http2 4.1.100: GHSA-xpw8-rcwv-8f8p (Netty mitigated this vulnerability as a Moderate but RedHat as Important. RedHat mitigation looks more correct).
Please upgrade Keycloak and check if any other packages could contribute to this issue.
Version
22.0.4
Expected behavior
Keycloak is not vulnerable
Actual behavior
Vulnerable package exist
How to Reproduce?
Anything else?
No response
Metadata
Metadata
Assignees
Labels
area/dist/quarkuskind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedteam/cloud-native