Back

MEDIUM

keycloak: failedLogin Event not sent to BruteForceProtector when using Post Login Flow with Conditional-OTP

Published Mar 24, 2020

Description

A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.

Affected products

Remediation

No remediation recorded yet.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 24, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 23, 2020
ENISA EUVD
Assigner redhat
Published Mar 24, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2021-1973 GHSA-4GF2-XV97-63M2