Related Vulnerabilities: CVE-2021-3513  

A security issue was found in keycloak where brute force attack is possible even when Permanent lockout feature is enabled because of the wrong error message displayed when wrong credentials entered.

Severity Medium

Remote Yes

Type Information disclosure

Description

A security issue was found in keycloak where brute force attack is possible even when Permanent lockout feature is enabled because of the wrong error message displayed when wrong credentials entered.

AVG-1332 keycloak 12.0.4-1 High Vulnerable

https://bugzilla.redhat.com/show_bug.cgi?id=1953439
https://issues.redhat.com/browse/KEYCLOAK-17835