Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.keycloak/keycloak-services
  4. ›
  5. GHSA-8wm9-24qg-m5qj

GHSA-8wm9-24qg-m5qj: Duplicate Advisory: Keycloak has a brute force login protection bypass

September 3, 2024 (updated September 17, 2024)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-gc7q-jgjv-vjr2. This link is maintained to preserve external references.

Original Description

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.

References

  • access.redhat.com/errata/RHSA-2024:6493
  • access.redhat.com/errata/RHSA-2024:6494
  • access.redhat.com/errata/RHSA-2024:6495
  • access.redhat.com/errata/RHSA-2024:6497
  • access.redhat.com/errata/RHSA-2024:6499
  • access.redhat.com/errata/RHSA-2024:6500
  • access.redhat.com/errata/RHSA-2024:6501
  • access.redhat.com/security/cve/CVE-2024-4629
  • bugzilla.redhat.com/show_bug.cgi?id=2276761
  • github.com/advisories/GHSA-8wm9-24qg-m5qj
  • github.com/keycloak/keycloak
  • nvd.nist.gov/vuln/detail/CVE-2024-4629

Code Behaviors & Features

Detect and mitigate GHSA-8wm9-24qg-m5qj with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 24.0.4

Fixed versions

  • 24.0.4

Solution

Upgrade to version 24.0.4 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-837: Improper Enforcement of a Single, Unique Action

Source file

maven/org.keycloak/keycloak-services/GHSA-8wm9-24qg-m5qj.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Mon, 12 May 2025 12:14:37 +0000.