HIGH 7.5 Maven
Incorrect implementation of lockout feature in Keycloak
GHSA-xv7h-95r7-595j · CVE-2021-3513
Published · Modified
Description
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
Ready to move
Start Securing
Free, no credit card | First findings in minutes