PT-2020-2664 · Red Hat · Keycloak

Published

2020-03-24

·

Updated

2025-11-21

·

CVE-2020-1744

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 9.0.1
Description A flaw was found in Keycloak when configuring a Conditional OTP Authentication Flow as a post login flow of an IDP. The failure login events for OTP are not being sent to the brute force protection event queue, resulting in the BruteForceProtector not handling these events. This could allow a remote attacker to gain unauthorized access to protected information due to errors in the Conditional OTP Authentication Flow configuration.
Recommendations For versions prior to 9.0.1, update to version 9.0.1 or later to resolve the issue. As a temporary workaround, consider disabling the Conditional OTP Authentication Flow until a patch is available. Restrict access to the IDP post login flow to minimize the risk of exploitation. Avoid using the OTP authentication mechanism in the affected flow until the issue is resolved.

Fix

Information Disclosure

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

BDU:2020-02708
CVE-2020-1744
GHSA-4GF2-XV97-63M2
OPENSUSE-SU-2024:10615-1
OPENSUSE-SU-2024:14244-1
OPENSUSE-SU-2024:14536-1
OPENSUSE-SU-2025:15605-1
OPENSUSE-SU-2025:15753-1
RHSA-2020:0945
RHSA-2020:0946
RHSA-2020:0947

Affected Products

Keycloak