CVE Vulnerabilities

CVE-2024-1722

Overly Restrictive Account Lockout Mechanism

Published: Feb 29, 2024 | Modified: Feb 14, 2025
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

Weakness

The product contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

Affected Software

Name Vendor Start Version End Version
Keycloak Redhat 23.0.5 (including) 23.0.5 (including)

Potential Mitigations

References