PT-2020-2664 · Red Hat · Keycloak
Published
2020-03-24
·
Updated
2025-11-21
·
CVE-2020-1744
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 9.0.1
Description
A flaw was found in Keycloak when configuring a Conditional OTP Authentication Flow as a post login flow of an IDP. The failure login events for OTP are not being sent to the brute force protection event queue, resulting in the BruteForceProtector not handling these events. This could allow a remote attacker to gain unauthorized access to protected information due to errors in the Conditional OTP Authentication Flow configuration.
Recommendations
For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the Conditional OTP Authentication Flow until a patch is available. Restrict access to the IDP post login flow to minimize the risk of exploitation. Avoid using the OTP authentication mechanism in the affected flow until the issue is resolved.
Fix
Information Disclosure
Improper Handling of Exceptional Conditions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Keycloak