keycloak: failedLogin Event not sent to BruteForceProtector when using Post Login Flow with Conditional-OTP
Published Mar 24, 2020
5.6
MEDIUMCVSS 3.1
EPSS 1.13%
Description
A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
Affected products
-
- Version all keycloak versions prior to 9.0.1StatusaffectedConstraints-
- Version
No data.
Red Hat Runtimes Spring Boot 2.2.6
keycloak
Fixed · RHSA-2020:2252
Red Hat Single Sign-On 7.3
n/a
Fixed · RHSA-2020:0951
Red Hat Single Sign-On 7.3 for RHEL 6
rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el6sso
Fixed · RHSA-2020:0945
Red Hat Single Sign-On 7.3 for RHEL 7
rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el7sso
Fixed · RHSA-2020:0946
Red Hat Single Sign-On 7.3 for RHEL 8
rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el8sso
Fixed · RHSA-2020:0947
Text-Only RHOAR
n/a
Fixed · RHSA-2020:2905
Red Hat Fuse 7
keycloak
Not affected
Red Hat OpenShift Application Runtimes
keycloak
Affected
Red Hat support for Spring Boot
keycloak
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Runtimes Spring Boot 2.2.6 | keycloak | Fixed | RHSA-2020:2252 |
| Red Hat Single Sign-On 7.3 | n/a | Fixed | RHSA-2020:0951 |
| Red Hat Single Sign-On 7.3 for RHEL 6 | rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el6sso | Fixed | RHSA-2020:0945 |
| Red Hat Single Sign-On 7.3 for RHEL 7 | rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el7sso | Fixed | RHSA-2020:0946 |
| Red Hat Single Sign-On 7.3 for RHEL 8 | rh-sso7-keycloak-0:4.8.18-1.Final_redhat_00001.1.el8sso | Fixed | RHSA-2020:0947 |
| Text-Only RHOAR | n/a | Fixed | RHSA-2020:2905 |
| Red Hat Fuse 7 | keycloak | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | keycloak | Affected | n/a |
| Red Hat support for Spring Boot | keycloak | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2020-1744 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1805792 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1744 Issue TrackingVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1973 Advisory
- https://github.com/advisories/GHSA-4gf2-xv97-63m2 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-1744
- https://www.cve.org/CVERecord?id=CVE-2020-1744
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2020-1744 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1805792 | Issue Tracking | |
| https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2020-1744 | Issue TrackingVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-1973 | Advisory | |
| https://github.com/advisories/GHSA-4gf2-xv97-63m2 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-1744 | ||
| https://www.cve.org/CVERecord?id=CVE-2020-1744 |
Change history (0)
No recorded changes yet.