Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Incorrect implementation of lockout feature in Keycloak

GHSA-xv7h-95r7-595j · CVE-2021-3513

Published · Modified

Description

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

Ready to move

Start Securing

Free, no credit card | First findings in minutes