A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.
                
            Metrics
Affected Vendors & Products
References
        History
                    Mon, 25 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 25 Nov 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | org.keycloak:keycloak-services: Keycloak Denial of Service | Org.keycloak:keycloak-services: keycloak denial of service | 
| First Time appeared | Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat red Hat Single Sign On | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp cpe:/a:redhat:red_hat_single_sign_on:7 | |
| Vendors & Products | Redhat jboss Enterprise Application Platform Redhat jbosseapxp Redhat red Hat Single Sign On | |
| References |  | 
 | 
Fri, 22 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity. | |
| Title | org.keycloak:keycloak-services: Keycloak Denial of Service | |
| First Time appeared | Redhat Redhat build Keycloak | |
| Weaknesses | CWE-1333 | |
| CPEs | cpe:/a:redhat:build_keycloak:24 cpe:/a:redhat:build_keycloak:24::el9 cpe:/a:redhat:build_keycloak:26 cpe:/a:redhat:build_keycloak:26.0::el9 | |
| Vendors & Products | Redhat Redhat build Keycloak | |
| References |  | |
| Metrics | threat_severity 
 | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2024-11-25T07:37:04.542Z
Updated: 2025-08-30T09:15:16.321Z
Reserved: 2024-10-23T02:00:58.671Z
Link: CVE-2024-10270
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-25T17:15:04.831Z
 NVD
                        NVD
                    Status : Received
Published: 2024-11-25T08:15:03.747
Modified: 2024-11-25T08:15:03.747
Link: CVE-2024-10270
 Redhat
                        Redhat