Skip to main content

Overly Restrictive Account Lockout Mechanism

CVE-2024-1722

Severity Low
Score 3.7/10

Summary

A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in. This issue affects the package org.keycloak:keycloak-services versions through 23.0.7, and 25.0.3. This shares same fix with CVE-2021-3754.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • LOW

CWE-645 - Overly Restrictive Account Lockout Mechanism

The software contains an account lockout protection mechanism, but the mechanism is too restrictive and can be triggered too easily, which allows attackers to deny service to legitimate users by causing their accounts to be locked out.

Advisory Timeline

  • Published