MEDIUM6.5
GHSA-gc7q-jgjv-vjr2
Keycloak Services has a potential bypass of brute force protection
Quick fix
GHSA-gc7q-jgjv-vjr2 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.
# pom.xml: bump <version>22.0.12</version> for org.keycloak:keycloak-servicesDetails
If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.
**Acknowledgements:** Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-services
Introduced in:
0Fixed in: 22.0.12Fix
# pom.xml: bump <version>22.0.12</version> for org.keycloak:keycloak-servicesMaven/org.keycloak:keycloak-services
Introduced in:
23.0.0Fixed in: 24.0.7Fix
# pom.xml: bump <version>24.0.7</version> for org.keycloak:keycloak-servicesMaven/org.keycloak:keycloak-services
Introduced in:
25.0.0Fixed in: 25.0.4Fix
# pom.xml: bump <version>25.0.4</version> for org.keycloak:keycloak-servicesReferences
- https://github.com/keycloak/keycloak/security/advisories/GHSA-gc7q-jgjv-vjr2[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-4629[ADVISORY]
- https://github.com/keycloak/keycloak/commit/d78b3072ffffbff3954bf9f3181e3daf8e93c1ab[WEB]
- https://github.com/keycloak/keycloak/commit/c8053dd812d9b9f05b293f901b9dc39e061ebb88[WEB]
- https://github.com/keycloak/keycloak/commit/b25c28458a562abda2f84fc684e59cce8577e562[WEB]
- https://github.com/keycloak/keycloak/commit/99f92ad5fff5555d53930c2d32f8be3e08c514c1[WEB]
- https://github.com/keycloak/keycloak/commit/461fa631dc55b9739c9ed8c49de9f5b213955200[WEB]
- https://github.com/keycloak/keycloak/commit/2fb358e1a21c5387cdc11100ce3562b4dcfe5416[WEB]
- https://github.com/keycloak/keycloak[PACKAGE]
- https://bugzilla.redhat.com/show_bug.cgi?id=2276761[WEB]
- https://access.redhat.com/security/cve/CVE-2024-4629[WEB]
- https://access.redhat.com/errata/RHSA-2024:6501[WEB]
- https://access.redhat.com/errata/RHSA-2024:6500[WEB]
- https://access.redhat.com/errata/RHSA-2024:6499[WEB]
- https://access.redhat.com/errata/RHSA-2024:6497[WEB]
- https://access.redhat.com/errata/RHSA-2024:6495[WEB]
- https://access.redhat.com/errata/RHSA-2024:6494[WEB]
- https://access.redhat.com/errata/RHSA-2024:6493[WEB]