SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1744

A flaw was found in keycloak before version 9.0.1.

MEDIUM 5.6EPSS 1.13%

Does this matter?

Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.

Description

A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.

CVSS 3.1
5.6 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
EPSS
1.13% probability · 65th percentile
CISA KEV
Not listed
Weakness
CWE-755
Affected
redhat/keycloak
Source
secalert@redhat.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.