Lack of protection against brute force attacks In keycloak-connect
Description
Keycloak Improper Bruteforce Detection A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.4.0 | ||
maven | 4.6.0.final |
Aliases
1. 2. 3. 4. 5. 6. 7. 8.
References
1.