QID 980852
QID 980852: Java (maven) Security Update for org.keycloak:keycloak-core (GHSA-4gf2-xv97-63m2)
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4gf2-xv97-63m2 for updates pertaining to this vulnerability.
Vendor References
- GHSA-4gf2-xv97-63m2 -
github.com/advisories/GHSA-4gf2-xv97-63m2
CVEs related to QID 980852
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4gf2-xv97-63m2 | org.keycloak:keycloak-core |
|