---
id: CVE-2024-1249
title: >-
  A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which
  allows unvalidated cross-origin messages
summary: >-
  A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which
  allows unvalidated cross-origin messages. This flaw allows attackers to
  coordinate and send millions of requests in seconds using simple code,
  significantly i…
severity: high
cvss: 7.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H'
cwe:
  - CWE-346
vendor: Red Hat
product: keycloak
affected:
  - keycloak >= 21.1.0 < 22.0.10
  - keycloak >= 23.0.0 < 24.0.3
  - keycloak
  - rhbk/keycloak-operator-bundle (all versions)
  - rhbk/keycloak-rhel9 (all versions)
  - rhbk/keycloak-rhel9-operator (all versions)
  - keycloak
  - rh-sso7-keycloak (all versions)
  - rh-sso7-keycloak (all versions)
  - rh-sso7-keycloak (all versions)
  - rh-sso-7/sso76-openshift-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-data-index-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-ephemeral-rhel8 (all versions)
  - openshift-serverless-1/logic-jobs-service-postgresql-rhel8 (all versions)
  - openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8 (all versions)
  - openshift-serverless-1/logic-operator-bundle (all versions)
  - openshift-serverless-1/logic-rhel8-operator (all versions)
  - openshift-serverless-1/logic-swf-builder-rhel8 (all versions)
  - openshift-serverless-1/logic-swf-devmode-rhel8 (all versions)
  - rh-sso7-keycloak
  - mta/mta-ui-rhel9 (all versions)
  - mta/mta-ui-rhel9
  - keycloak (all versions)
  - keycloak
  - keycloak (all versions)
  - rhdh/rhdh-hub-rhel9
  - keycloak
  - keycloak
  - keycloak
  - keycloak-adapter-eap6
  - keycloak-adapter-sso7_2-eap6
  - keycloak-adapter-sso7_3-eap6
  - keycloak-adapter-sso7_4-eap6
  - keycloak-adapter-sso7_5-eap6
  - org.keycloak-keycloak-parent
  - rh-sso7-keycloak
  - keycloak-core (all versions)
  - keycloak-core
  - keycloak
  - keycloak (all versions)
  - keycloak
published: '2024-04-17'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:17:25.350'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1249'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2024:1860'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1861'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1862'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1864'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1866'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:4057'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1249'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2262918'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2024:1860'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1861'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1862'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1864'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1866'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1867'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:1868'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:2945'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/errata/RHSA-2024:4057'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://access.redhat.com/security/cve/CVE-2024-1249'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2262918'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1249.json
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-1249'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-1249'
tags:
  - nvd
  - cve.org
  - csaf
  - vex
  - red-hat
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2024-04-25T17:33:02.839974Z'
epss: 0.00448
epssPercentile: 0.36198
ingestedAt: '2026-09-08T20:10:03.221Z'
patched:
  - single_sign_on_7_6_for_rhel_7_server
  - middleware_containers_for_openshift
  - openshift_serverless 1.33
  - single_sign_on_7_6_for_rhel 8
  - build_of_keycloak 22
  - single_sign_on_7_6_for_rhel 9
  - rhsso 7.6.8
  - amq_broker 7
  - build_of_keycloak 22.0.10
---

## Overview

A flaw was found in Keycloak's OIDC component in the "checkLoginIframe," which allows unvalidated cross-origin messages. This flaw allows attackers to coordinate and send millions of requests in seconds using simple code, significantly impacting the application's availability without proper origin validation for incoming messages.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **RHSA-2024:1860** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 7 Server · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1860)
- **RHSA-2024:1864** · Red Hat · fixed in: Middleware Containers for OpenShift · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1864)
- **RHSA-2024:4057** · Red Hat · fixed in: Red Hat OpenShift Serverless 1.33 · released 2024-06-24 · [advisory](https://access.redhat.com/errata/RHSA-2024:4057)
- **RHSA-2024:1861** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 8 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1861)
- **RHSA-2024:1867** · Red Hat · fixed in: Red Hat build of Keycloak 22 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1867)
- **RHSA-2024:1862** · Red Hat · fixed in: Red Hat Single Sign-On 7.6 for RHEL 9 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1862)
- **RHSA-2024:1866** · Red Hat · fixed in: RHSSO 7.6.8 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1866)
- **RHSA-2024:2945** · Red Hat · fixed in: Red Hat AMQ Broker 7 · released 2024-05-21 · [advisory](https://access.redhat.com/errata/RHSA-2024:2945)
- **RHSA-2024:1868** · Red Hat · fixed in: Red Hat build of Keycloak 22.0.10 · released 2024-04-16 · [advisory](https://access.redhat.com/errata/RHSA-2024:1868)
- **Red Hat VEX** · Important · affected: Migration Toolkit for Applications 6, Red Hat build of Apicurio Registry 2, Red Hat Decision Manager 7, Red Hat JBoss Enterprise Application Platform 6, Red Hat JBoss Enterprise Application Platform 7, Red Hat Process Automation 7 · no fix planned: Red Hat JBoss Enterprise Application Platform 6, Migration Toolkit for Applications 6, Red Hat Process Automation 7, Red Hat build of Apicurio Registry 2, … · updated 2026-09-08 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-1249.json)
