Description
A flaw was found in keycloak-model-infinispan in keycloak versions before 14.0.0 where authenticationSessions map in RootAuthenticationSessionEntity grows boundlessly which could lead to a DoS attack.
Remediation
References
https://bugzilla.redhat.com/show_bug.cgi?id=1979638
Related Vulnerabilities
CVE-2017-5651 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-31166 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2022-47551 Vulnerability in maven package io.apiman:apiman-manager-api-rest-impl
CVE-2014-9970 Vulnerability in maven package org.jasypt:jasypt