[MAVEN:GHSA-CQ42-VHV7-XR7P] Keycloak Denial of Service via account lockout

Severity Low
Affected Packages 1
Fixed Packages 1

In any realm set with "User (Self) registration" a user that is registered with a username in email format can be "locked out" (denied from logging in) using his username.

Package Affected Version
pkg:maven/org.keycloak/keycloak-services < 24.0.0
Package Fixed Version
pkg:maven/org.keycloak/keycloak-services = 24.0.0
ID
MAVEN:GHSA-CQ42-VHV7-XR7P
Severity
low
URL
https://github.com/advisories/GHSA-cq42-vhv7-xr7p
Published
2024-06-12T19:42:21
(3 months ago)
Modified
2024-06-12T19:42:24
(3 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services < 24.0.0
Fixed pkg:maven/org.keycloak/keycloak-services org.keycloak keycloak-services = 24.0.0
Loading...