From dc47450f7bb0189a8c34b8c241b03cd812aa03d8 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 17 Sep 2024 22:23:52 +0000 Subject: [PATCH] Publish GHSA-8wm9-24qg-m5qj --- .../2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json | 9 +++++---- 1 file changed, 5 insertions(+), 4 deletions(-) diff --git a/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json b/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json index 6913e69a721..910adb0f324 100644 --- a/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json +++ b/advisories/github-reviewed/2024/09/GHSA-8wm9-24qg-m5qj/GHSA-8wm9-24qg-m5qj.json @@ -1,13 +1,14 @@ { "schema_version": "1.4.0", "id": "GHSA-8wm9-24qg-m5qj", - "modified": "2024-09-09T21:31:21Z", + "modified": "2024-09-17T22:22:26Z", "published": "2024-09-03T21:31:12Z", + "withdrawn": "2024-09-17T22:22:26Z", "aliases": [ - "CVE-2024-4629" + ], - "summary": "Keycloak has a brute force login protection bypass", - "details": "A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.", + "summary": "Duplicate Advisory: Keycloak has a brute force login protection bypass", + "details": "## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-gc7q-jgjv-vjr2. This link is maintained to preserve external references.\n\n## Original Description\nA vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the timing of login attempts. By initiating multiple login requests simultaneously, attackers can exceed the configured limits for failed attempts before the system locks them out. This timing loophole enables attackers to make more guesses at passwords than intended, potentially compromising account security on affected systems.", "severity": [ { "type": "CVSS_V3",