CVE-2021-3513
published 2022-08-22CVE-2021-3513: A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.66%
47.5th percentile
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | < 13.0.0 | 13.0.0 |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
keycloak: Brute force attack is possible even after the account lockout
vendor_redhat·2021-04-26·CVSS 7.5
CVE-2021-3513 [HIGH] CWE-522 keycloak: Brute force attack is possible even after the account lockout
keycloak: Brute force attack is possible even after the account lockout
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
OSV
Incorrect implementation of lockout feature in Keycloak
osv·2022-08-23
CVE-2021-3513 [HIGH] Incorrect implementation of lockout feature in Keycloak
Incorrect implementation of lockout feature in Keycloak
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
GHSA
Incorrect implementation of lockout feature in Keycloak
ghsa·2022-08-23
CVE-2021-3513 [HIGH] CWE-209 Incorrect implementation of lockout feature in Keycloak
Incorrect implementation of lockout feature in Keycloak
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-22
Published