CyberRota Analysis
AI-GeneratedKeycloak's user-event metrics recording is vulnerable to a denial-of-service attack due to the logging of raw error messages from failed account operations as Prometheus metric labels. An authenticated user can exploit this flaw by generating numerous unique error messages, leading to memory exhaustion and potential service outages. Organizations using Keycloak with metrics enabled should prioritize addressing this vulnerability to prevent disruptions in service availability.
Original NVD Description
A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error messages from failed account operations as Prometheus metric labels. Because these error messages can include user-supplied input like nonexistent client IDs, an authenticated user can create a massive number of unique metric entries, eventually exhausting system memory and causing the service to crash or become unavailable.
Related CVEs
Other vulnerabilities affecting the same vendor(s)