SB2024091823 - Brute-force protection bypass in Keycloak
Published: September 18, 2024
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Restriction of Excessive Authentication Attempts (CVE-ID: CVE-2024-4629)
The vulnerability allows a remote attacker to perform a brute-force attack.
The vulnerability exists due to an error when handling unsuccessful login attempts. A remote attacker can initiate multiple login requests simultaneously and bypass the configured limits for failed attempts before the system locks them out.
Remediation
Install update from vendor's website.