GHSA-xv7h-95r7-595j
GitHub Security Advisory
Incorrect implementation of lockout feature in Keycloak
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
Affected Packages
Maven
org.keycloak:keycloak-parent
Affected versions:
0
(fixed in 13.0.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: September 22, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.