Keycloak vulnerable to uncontrolled resource consumption
        
  High severity
        
          GitHub Reviewed
      
        Published
          Oct 18, 2018 
          to the GitHub Advisory Database
          •
          Updated Jan 8, 2023 
      
  
Description
        Published to the GitHub Advisory Database
      Oct 18, 2018 
    
  
        Reviewed
      Jun 16, 2020 
    
  
        Last updated
      Jan 8, 2023 
    
  
JBoss KeyCloak versions prior to 1.0.3.Final allow remote attackers to create a denial of service (resource consumption) by supplying a large value in the size parameter to auth/qrcode, related to QR code generation.
References