{
  "document": {
    "aggregate_severity": {
      "namespace": "https://access.redhat.com/security/updates/classification/",
      "text": "Important"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright © Red Hat, Inc. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Red Hat Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-6563.json"
      }
    ],
    "title": "keycloak: offline session token DoS",
    "tracking": {
      "current_release_date": "2026-08-04T07:15:30+00:00",
      "generator": {
        "date": "2026-08-04T07:15:30+00:00",
        "engine": {
          "name": "Red Hat SDEngine",
          "version": "5.3.8"
        }
      },
      "id": "CVE-2023-6563",
      "initial_release_date": "2023-12-14T00:00:00+00:00",
      "revision_history": [
        {
          "date": "2023-12-14T00:00:00+00:00",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-08-04T07:10:33+00:00",
          "number": "2",
          "summary": "Current version"
        },
        {
          "date": "2026-08-04T07:15:30+00:00",
          "number": "3",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "3"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Red Hat Build of Keycloak",
                "product": {
                  "name": "Red Hat Build of Keycloak",
                  "product_id": "red_hat_build_of_keycloak",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:build_keycloak:"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Build of Keycloak"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Middleware Containers for OpenShift",
                "product": {
                  "name": "Middleware Containers for OpenShift",
                  "product_id": "8Base-RHOSE-Middleware",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:rhosemc:1.0::el8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat OpenShift Enterprise"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Single Sign-On 7.6.6",
                "product": {
                  "name": "Single Sign-On 7.6.6",
                  "product_id": "Single Sign-On 7.6.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7.6.6"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7.6 for RHEL 9",
                "product": {
                  "name": "Red Hat Single Sign-On 7.6 for RHEL 9",
                  "product_id": "9Base-RHSSO-7.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7.6::el9"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7.6 for RHEL 8",
                "product": {
                  "name": "Red Hat Single Sign-On 7.6 for RHEL 8",
                  "product_id": "8Base-RHSSO-7.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7.6::el8"
                  }
                }
              },
              {
                "category": "product_name",
                "name": "Red Hat Single Sign-On 7.6 for RHEL 7 Server",
                "product": {
                  "name": "Red Hat Single Sign-On 7.6 for RHEL 7 Server",
                  "product_id": "7Server-RHSSO-7.6",
                  "product_identification_helper": {
                    "cpe": "cpe:/a:redhat:red_hat_single_sign_on:7.6::el7"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Red Hat Single Sign-On"
          },
          {
            "category": "product_version",
            "name": "keycloak-core",
            "product": {
              "name": "keycloak-core",
              "product_id": "keycloak-core",
              "product_identification_helper": {
                "purl": "pkg:maven/org.keycloak/keycloak-core?type=jar"
              }
            }
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
                "product": {
                  "name": "rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
                  "product_id": "rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c?arch=amd64&repository_url=registry.redhat.io/rh-sso-7/sso7-rhel8-operator-bundle&tag=7.6.6-2"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
                "product": {
                  "name": "rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
                  "product_id": "rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
                  "product_identification_helper": {
                    "purl": "pkg:oci/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b?arch=amd64&repository_url=registry.redhat.io/rh-sso-7/sso76-openshift-rhel8&tag=7.6-38"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
                "product": {
                  "name": "rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
                  "product_id": "rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
                  "product_identification_helper": {
                    "purl": "pkg:oci/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662?arch=s390x&repository_url=registry.redhat.io/rh-sso-7/sso76-openshift-rhel8&tag=7.6-38"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "s390x"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
                "product": {
                  "name": "rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
                  "product_id": "rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
                  "product_identification_helper": {
                    "purl": "pkg:oci/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696?arch=ppc64le&repository_url=registry.redhat.io/rh-sso-7/sso76-openshift-rhel8&tag=7.6-38"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "ppc64le"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el9sso?arch=src"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el8sso?arch=src"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el7sso?arch=src"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "src"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el9sso?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                  "product_id": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak-server@18.0.11-2.redhat_00003.1.el9sso?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el8sso?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                  "product_id": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak-server@18.0.11-2.redhat_00003.1.el8sso?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                  "product_id": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak@18.0.11-2.redhat_00003.1.el7sso?arch=noarch"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                "product": {
                  "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                  "product_id": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/redhat/rh-sso7-keycloak-server@18.0.11-2.redhat_00003.1.el7sso?arch=noarch"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "Red Hat"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server",
          "product_id": "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
        "relates_to_product_reference": "7Server-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server",
          "product_id": "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
        "relates_to_product_reference": "7Server-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 7 Server",
          "product_id": "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
        "relates_to_product_reference": "7Server-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64 as a component of Middleware Containers for OpenShift",
          "product_id": "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64"
        },
        "product_reference": "rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
        "relates_to_product_reference": "8Base-RHOSE-Middleware"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x as a component of Middleware Containers for OpenShift",
          "product_id": "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x"
        },
        "product_reference": "rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
        "relates_to_product_reference": "8Base-RHOSE-Middleware"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le as a component of Middleware Containers for OpenShift",
          "product_id": "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le"
        },
        "product_reference": "rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
        "relates_to_product_reference": "8Base-RHOSE-Middleware"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64 as a component of Middleware Containers for OpenShift",
          "product_id": "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64"
        },
        "product_reference": "rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
        "relates_to_product_reference": "8Base-RHOSE-Middleware"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8",
          "product_id": "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
        "relates_to_product_reference": "8Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 8",
          "product_id": "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
        "relates_to_product_reference": "8Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 8",
          "product_id": "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
        "relates_to_product_reference": "8Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 9",
          "product_id": "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
        "relates_to_product_reference": "9Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src as a component of Red Hat Single Sign-On 7.6 for RHEL 9",
          "product_id": "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src"
        },
        "product_reference": "rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
        "relates_to_product_reference": "9Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch as a component of Red Hat Single Sign-On 7.6 for RHEL 9",
          "product_id": "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch"
        },
        "product_reference": "rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
        "relates_to_product_reference": "9Base-RHSSO-7.6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "keycloak-core as a component of Red Hat Build of Keycloak",
          "product_id": "red_hat_build_of_keycloak:keycloak-core"
        },
        "product_reference": "keycloak-core",
        "relates_to_product_reference": "red_hat_build_of_keycloak"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-6563",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "discovery_date": "2023-12-06T00:00:00+00:00",
      "flags": [
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "red_hat_build_of_keycloak:keycloak-core"
          ]
        }
      ],
      "ids": [
        {
          "system_name": "Red Hat Bugzilla ID",
          "text": "2253308"
        }
      ],
      "notes": [
        {
          "category": "description",
          "text": "An unconstrained memory consumption vulnerability was discovered in Keycloak. It can be triggered in environments which have millions of offline tokens (> 500,000 users with each having at least 2 saved sessions). If an attacker creates two or more user sessions and then open the \"consents\" tab of the admin User Interface, the UI attempts to load a huge number of offline client sessions leading to excessive memory and CPU consumption which could potentially crash the entire system.",
          "title": "Vulnerability description"
        },
        {
          "category": "summary",
          "text": "keycloak: offline session token DoS",
          "title": "Vulnerability summary"
        },
        {
          "category": "other",
          "text": "While this vulnerability can enable complete compromise of system availability, it is not possible to be triggered in every environment. The impact is rated as Important due to several preconditions (number of users and how many sessions each user has) which are beyond an attacker's control.",
          "title": "Statement"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
          "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
          "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
          "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
          "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
          "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
          "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
          "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
          "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
          "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
          "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
          "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
          "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
          "Single Sign-On 7.6.6"
        ],
        "known_not_affected": [
          "red_hat_build_of_keycloak:keycloak-core"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2023-6563"
        },
        {
          "category": "external",
          "summary": "RHBZ#2253308",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2253308"
        },
        {
          "category": "external",
          "summary": "https://www.cve.org/CVERecord?id=CVE-2023-6563",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-6563"
        },
        {
          "category": "external",
          "summary": "https://nvd.nist.gov/vuln/detail/CVE-2023-6563",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-6563"
        },
        {
          "category": "external",
          "summary": "https://github.com/keycloak/keycloak/issues/13340",
          "url": "https://github.com/keycloak/keycloak/issues/13340"
        }
      ],
      "release_date": "2023-12-14T00:00:00+00:00",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2023-12-14T19:01:36+00:00",
          "details": "Before applying this update, make sure all previously released errata\nrelevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2023:7854"
        },
        {
          "category": "vendor_fix",
          "date": "2023-12-14T19:53:20+00:00",
          "details": "To update to the latest Red Hat Single Sign-On 7.6.6 for OpenShift image, follow these steps to pull in the content:\n\n1. On your main hosts, ensure you are logged into the CLI as a cluster administrator or user with project administrator access to the global \"openshift\" project. For example:\n\n$ oc login -u system:admin\n\n2. Update the core set of Red Hat Single Sign-On resources for OpenShift in the \"openshift\" project by running the following commands:\n\n$ for resource in sso76-image-stream.json \\\nsso76-https.json \\\nsso76-mysql.json \\\nsso76-mysql-persistent.json \\\nsso76-postgresql.json \\\nsso76-postgresql-persistent.json \\\nsso76-x509-https.json \\\nsso76-x509-mysql-persistent.json \\\nsso76-x509-postgresql-persistent.json\ndo\noc replace -n openshift --force -f \\\nhttps://raw.githubusercontent.com/jboss-container-images/redhat-sso-7-openshift-image/v7.6.6.GA/templates/${resource}\ndone\n\n3. Install the Red Hat Single Sign-On 7.6.6 for OpenShift streams in the \"openshift\" project by running the following command:\n\n$ oc -n openshift import-image redhat-sso76-openshift:1.0",
          "product_ids": [
            "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2023:7857"
        },
        {
          "category": "vendor_fix",
          "date": "2023-12-14T19:01:20+00:00",
          "details": "Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2023:7856"
        },
        {
          "category": "vendor_fix",
          "date": "2023-12-14T19:00:48+00:00",
          "details": "Before applying this update, make sure all previously released errata relevant to your system have been applied.\n\nFor details on how to apply this update, refer to:\n\nhttps://access.redhat.com/articles/11258",
          "product_ids": [
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2023:7855"
        },
        {
          "category": "vendor_fix",
          "date": "2023-12-14T19:04:26+00:00",
          "details": "Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.\n\nThe References section of this erratum contains a download link (you must log in to download the update).",
          "product_ids": [
            "Single Sign-On 7.6.6"
          ],
          "url": "https://access.redhat.com/errata/RHSA-2023:7858"
        },
        {
          "category": "workaround",
          "details": "There are three main options to prevent exploitation:\n1) If you are using a reverse proxy, block the consents URL.\n2) This option is less effective: remove the consents application tab from the account console theme.\n3) This option has a significant negative impact on end users: entirely disable offline user profiles.",
          "product_ids": [
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "Single Sign-On 7.6.6"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.7,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "Single Sign-On 7.6.6",
            "red_hat_build_of_keycloak:keycloak-core"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important",
          "product_ids": [
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el7sso.src",
            "7Server-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el7sso.noarch",
            "8Base-RHOSE-Middleware:rh-sso-7/sso7-rhel8-operator-bundle@sha256:4cbf1a09c7207f9f1ffc918b5e8a4adaa89938befc6d75040b3ddd505ab14f6c_amd64",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:05c8f187d183582102855c12ac856f361cc6a0bbd792675799bfc319694bc662_s390x",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:c65934aa7883ccd9655cd1e7e47899e97470e42cc32bbe5386cc64f88fd26696_ppc64le",
            "8Base-RHOSE-Middleware:rh-sso-7/sso76-openshift-rhel8@sha256:db235506ce5d840dc139a3cde4114939222df6abb0901efaaff4f9ddbc495b9b_amd64",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el8sso.src",
            "8Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el8sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-0:18.0.11-2.redhat_00003.1.el9sso.src",
            "9Base-RHSSO-7.6:rh-sso7-keycloak-server-0:18.0.11-2.redhat_00003.1.el9sso.noarch",
            "Single Sign-On 7.6.6",
            "red_hat_build_of_keycloak:keycloak-core"
          ]
        }
      ],
      "title": "keycloak: offline session token DoS"
    }
  ]
}