Medium severity6.5OSV Advisory· Published Sep 3, 2024· Updated Jun 17, 2026
CVE-2024-4629
CVE-2024-4629
Description
A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.keycloak:keycloak-servicesMaven | < 22.0.12 | 22.0.12 |
org.keycloak:keycloak-servicesMaven | >= 23.0.0, < 24.0.7 | 24.0.7 |
org.keycloak:keycloak-servicesMaven | >= 25.0.0, < 25.0.4 | 25.0.4 |
Affected products
141.0-alpha-1, 1.0-alpha-1-12062013, 1.0-alpha-2, …+ 1 more
- (no CPE)range: 1.0-alpha-1, 1.0-alpha-1-12062013, 1.0-alpha-2, …
- cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*:*range: >=22.0,<22.012
cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:openshift_container_platform:4.11:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform:4.12:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_power:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_for_linuxone:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.10:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_platform_ibm_z_systems:4.9:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:redhat:single_sign-on:*:*:*:*:*:*:*:*range: >=7.6,<7.6.10
- cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
Patches
Vulnerability mechanics
References
20- access.redhat.com/errata/RHSA-2024:6493nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6494nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6495nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6497nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6499nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6500nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2024:6501nvdVendor AdvisoryWEB
- access.redhat.com/security/cve/CVE-2024-4629nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-gc7q-jgjv-vjr2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-4629ghsaADVISORY
- github.com/keycloak/keycloak/commit/2fb358e1a21c5387cdc11100ce3562b4dcfe5416ghsaWEB
- github.com/keycloak/keycloak/commit/461fa631dc55b9739c9ed8c49de9f5b213955200ghsaWEB
- github.com/keycloak/keycloak/commit/99f92ad5fff5555d53930c2d32f8be3e08c514c1ghsaWEB
- github.com/keycloak/keycloak/commit/b25c28458a562abda2f84fc684e59cce8577e562ghsaWEB
- github.com/keycloak/keycloak/commit/c8053dd812d9b9f05b293f901b9dc39e061ebb88ghsaWEB
- github.com/keycloak/keycloak/commit/d78b3072ffffbff3954bf9f3181e3daf8e93c1abghsaWEB
- github.com/keycloak/keycloak/security/advisories/GHSA-gc7q-jgjv-vjr2ghsaWEB
- github.com/hnsecurity/vulns/blob/main/HNS-2024-09-Keycloak.mdnvd
- security.humanativaspa.it/an-analysis-of-the-keycloak-authentication-system/nvd
News mentions
0No linked articles in our index yet.