CVE-2024-4629
published 2024-09-03CVE-2024-4629: A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating…
PriorityP336medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.79%
52.3th percentile
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | build_of_keycloak | >= 22.0 < 22.012 | 22.012 |
| redhat | keycloak | < 24.0.3 | 24.0.3 |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_linuxone | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_for_power | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | openshift_container_platform_ibm_z_systems | — | — |
| redhat | single_sign-on | >= 7.6 < 7.6.10 | 7.6.10 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Keycloak Services has a potential bypass of brute force protection
osv·2024-09-17
CVE-2024-4629 [MEDIUM] Keycloak Services has a potential bypass of brute force protection
Keycloak Services has a potential bypass of brute force protection
If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.
**Acknowledgements:**
Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.
GHSA
Keycloak Services has a potential bypass of brute force protection
ghsa·2024-09-17
CVE-2024-4629 [MEDIUM] CWE-307 Keycloak Services has a potential bypass of brute force protection
Keycloak Services has a potential bypass of brute force protection
If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.
**Acknowledgements:**
Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.
Red Hat
keycloak: potential bypass of brute force protection
vendor_redhat·2024-09-03·CVSS 6.5
CVE-2024-4629 [MEDIUM] CWE-837 keycloak: potential bypass of brute force protection
keycloak: potential bypass of brute force protection
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This t
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2024:6493https://access.redhat.com/errata/RHSA-2024:6494https://access.redhat.com/errata/RHSA-2024:6495https://access.redhat.com/errata/RHSA-2024:6497https://access.redhat.com/errata/RHSA-2024:6499https://access.redhat.com/errata/RHSA-2024:6500https://access.redhat.com/errata/RHSA-2024:6501https://access.redhat.com/security/cve/CVE-2024-4629https://bugzilla.redhat.com/show_bug.cgi?id=2276761https://github.com/hnsecurity/vulns/blob/main/HNS-2024-09-Keycloak.mdhttps://security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/
2024-09-03
Published