Back

MEDIUM

Keycloak: secondary factor bypass in step-up authentication

Published Apr 25, 2024

Description

A flaw was found in Keycloak, where it does not correctly validate its client step-up authentication in org.keycloak.authentication. This flaw allows a remote user authenticated with a password to register a false second authentication factor along with an existing one and bypass authentication.

Affected products

Remediation

Red Hat statement

Note that exploitation of this flaw requires several factors to be successful. The attacker must already have valid credentials within the system, without which there is no vulnerability, and the application must be configured to use the step-up flow, which is the only aspect of authentication bypassed by this flaw; the name and password restriction function as expected. Further, the impact effects of this flaw are limited to user-level and do not affect the system as a whole. For this reason, Red Hat Product Security has assessed this flaw to be Moderate security impact.

References (11)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Apr 25, 2024
Updated Nov 11, 2025
Reserved Jul 10, 2023

CISA Vulnrichment

Updated May 2, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

Severity Moderate
Public date Apr 15, 2024
Bugzilla 2221760

ENISA EUVD

Assigner redhat
Published Apr 25, 2024
Updated Nov 11, 2025