Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 Maven

Keycloak Services has a potential bypass of brute force protection

GHSA-gc7q-jgjv-vjr2 · CVE-2024-4629

Published · Modified

Description

If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.

Acknowledgements:
Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.

Ready to move

Start Securing

Free, no credit card | First findings in minutes