← Back

CVE-2024-4629

nvd nist
Published: Sep 3, 2024Modified: Jun 17, 2026

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 3.9 / Impact: 2.5
Source: NVD

Description

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.

Affected (12)

7 products
Keycloak
Build Of Keycloak
Single Sign On
Openshift Container Platform
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 24.0.3
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
From 22.0 to 22.012
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
From 7.6 to 7.6.10
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 9.0
Configuration E
8 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Redhat
Version 4.11
Version 4.12
Redhat
Version 4.10
Version 4.9
Redhat
Version 4.10
Version 4.9
Redhat
Version 4.10
Version 4.9
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 8.0

References (11)

Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Vendor Advisory
Source: secalert@redhat.com
Issue TrackingVendor Advisory

Timeline

No history available yet.