Keycloak: potential bypass of brute force protection
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.5epss 0.8%
exploitation probability
0.8%top 45% of all CVEs
observed exploitation
nono source reports it
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Affected products
keycloakRed Hat · Red Hat Build of KeycloakRed Hat · Red Hat build of Keycloak 22Red Hat · Red Hat JBoss Enterprise Application Platform 8Red Hat · Red Hat Single Sign-On 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 7Red Hat · Red Hat Single Sign-On 7.6 for RHEL 8Red Hat · Red Hat Single Sign-On 7.6 for RHEL 9Red Hat · RHEL-8 based Middleware ContainersReferences
https://access.redhat.com/errata/RHSA-2024:6493https://access.redhat.com/errata/RHSA-2024:6494https://access.redhat.com/errata/RHSA-2024:6495https://access.redhat.com/errata/RHSA-2024:6497https://access.redhat.com/errata/RHSA-2024:6499https://access.redhat.com/errata/RHSA-2024:6500https://access.redhat.com/errata/RHSA-2024:6501https://access.redhat.com/security/cve/CVE-2024-4629https://bugzilla.redhat.com/show_bug.cgi?id=2276761https://github.com/hnsecurity/vulns/blob/main/HNS-2024-09-Keycloak.mdhttps://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/