CVE Database
/

CVE-2021-3513

Back to search

CVE-2021-3513

Published: Aug 22, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.

VendorProductVersions

n/a

keycloak

affected
Fixed in keycloak v13.0.0.

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now