PT-2022-10443 · Red Hat · Keycloak

Michał Knapik

+2

·

Published

2022-08-22

·

Updated

2022-08-23

·

CVE-2021-3513

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified) Redhat Keycloak (affected versions not specified)
Description A flaw in the software allows a brute force attack to be possible, even when the permanent lockout feature is enabled. This is due to an incorrect error message being displayed when incorrect credentials are entered, posing the highest threat to confidentiality.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2021-3513
GHSA-XV7H-95R7-595J
RHSA-2021:3527
RHSA-2021:3528
RHSA-2021:3529

Affected Products

Keycloak