PT-2024-31946 · Red Hat · Keycloak

Maurizio Agazzini

·

Published

2024-09-03

·

Updated

2024-09-17

·

CVE-2024-4629

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A flaw in Keycloak allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Restriction of Excessive Authentication Attempts

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-4629
GHSA-8WM9-24QG-M5QJ
GHSA-GC7Q-JGJV-VJR2
RHSA-2024:6493
RHSA-2024:6494
RHSA-2024:6495

Affected Products

Keycloak