CVE-2024-4629

CVSS V2 None CVSS V3 None
Description
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
Overview
  • CVE ID
  • CVE-2024-4629
  • Assigner
  • redhat
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-09-03T19:42:01.318Z
  • Last Modified Date
  • 2024-09-03T20:20:42.938Z
References
Reference URL Reference Tags
https://access.redhat.com/security/cve/CVE-2024-4629 vdb-entry x_refsource_REDHAT
https://bugzilla.redhat.com/show_bug.cgi?id=2276761 issue-tracking x_refsource_REDHAT
History
Created Old Value New Value Data Type Notes
2024-09-04 13:02:29 Added to TrackCVE