VDB
Sign up
MEDIUM6.5

GHSA-gc7q-jgjv-vjr2

Keycloak Services has a potential bypass of brute force protection

Quick fix

GHSA-gc7q-jgjv-vjr2 — org.keycloak:keycloak-services: upgrade to the fixed version with the command below.

# pom.xml: bump <version>22.0.12</version> for org.keycloak:keycloak-services

Details

If an attacker launches many login attempts in parallel then the attacker can have more guesses at a password than the brute force protection configuration permits. This is due to the brute force check occurring before the brute force protector has locked the user.

**Acknowledgements:** Special thanks to Maurizio Agazzini for reporting this issue and helping us improve our project.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-services
Introduced in: 0Fixed in: 22.0.12
Fix# pom.xml: bump <version>22.0.12</version> for org.keycloak:keycloak-services
Maven/org.keycloak:keycloak-services
Introduced in: 23.0.0Fixed in: 24.0.7
Fix# pom.xml: bump <version>24.0.7</version> for org.keycloak:keycloak-services
Maven/org.keycloak:keycloak-services
Introduced in: 25.0.0Fixed in: 25.0.4
Fix# pom.xml: bump <version>25.0.4</version> for org.keycloak:keycloak-services

References