Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2024-4629: Improper Enforcement of a Single, Unique Action

0
Medium
VulnerabilityCVE-2024-4629cvecve-2024-4629
Published: Tue Sep 03 2024 (09/03/2024, 19:42:01 UTC)
Source: CVE Database V5

Description

A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.

Technical Details

Data Version
5.2
Assigner Short Name
redhat
Date Reserved
2024-05-07T20:47:03.184Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 692013a1ce2640f942c6ad51

Added to database: 11/21/2025, 7:24:17 AM

Last updated: 11/21/2025, 7:24:26 AM

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats