CVE Published: 27/07/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: redhat |
Vendor: Red Hat |
Product: keycloak Status : PUBLISHED
CVE-2017-2646 Description
It was found that when Keycloak before 2.5.5 receives a Logout request with a Extensions in the middle of the request, the SAMLSloRequestParser.parse() method ends in a infinite loop. An attacker could use this flaw to conduct denial of service attacks.