Описание
Keycloak Denial of Service via account lockout
In any realm set with "User (Self) registration" a user that is registered with a username in email format can be "locked out" (denied from logging in) using his username.
Ссылки
- https://github.com/keycloak/keycloak/security/advisories/GHSA-cq42-vhv7-xr7p
- https://nvd.nist.gov/vuln/detail/CVE-2024-1722
- https://github.com/keycloak/keycloak/issues/29603
- https://github.com/keycloak/keycloak/issues/29603#issuecomment-2127499627
- https://github.com/keycloak/keycloak/commit/f9708037383aa98741e4850447de64dc4a0d4b4e
- https://access.redhat.com/security/cve/CVE-2024-1722
- https://bugzilla.redhat.com/show_bug.cgi?id=2265389
Пакеты
org.keycloak:keycloak-services
< 24.0.0
24.0.0
Связанные уязвимости
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.
A flaw was found in Keycloak. In certain conditions, this issue may al ...
Уязвимость программного средства для управления идентификацией и доступом Keycloak, связанная с чрезмерно ограничительным механизмом блокировки учётных данных пользователя, позволяющая нарушителю заблокировать доступ пользователя к его учетной записи