Exposure of Sensitive Information in keycloak
Moderate severity
GitHub Reviewed
Published
Sep 20, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Mar 24, 2020
Reviewed
Sep 16, 2021
Published to the GitHub Advisory Database
Sep 20, 2021
Last updated
Feb 1, 2023
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
References