CVE-2023-6563

Aliases:GHSA-54f3-c6hg-865h
Advisory lineage Upstream: 0 Downstream: 3
Modified
Published: 14 Dec 2023, 18:01
Last modified:11 Nov 2025, 15:10

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
7.7 HIGH
v3.1 (cve.org)
EPSS Score
0.54% LOW
1% probability +0.23%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

14 Dec 2023, 18:01
Published
Vulnerability first disclosed
11 Nov 2025, 15:10
Last Modified
Vulnerability information updated

Description

An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the "consents" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.

CVSS Metrics

  • v3.1HIGHScore: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.54% Percentile: 68%

Techniques & Countermeasures

  • CWE-770Allocation of Resources Without Limits or Throttling

    The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Affected Systems

  • org.keycloakkeycloak-model-jpa

    < 21.0.0

  • redhatkeycloak

    < 21.0.0

  • redhatopenshift_container_platform

    4.11 | 4.12

  • redhatopenshift_container_platform_for_ibm_linuxone

    4.9 | 4.10

  • redhatopenshift_container_platform_for_power

    4.9 | 4.10

  • redhatsingle_sign-on

    7.6 | na

References (12)