CVE-2021-3513
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled.
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
HIGH · CVSS 7.5
EPSS 0.00201
Schedule remediation
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0