CVE-2021-3513: High severity red hat keycloak vulnerability
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
Other sources
Even though Permanent Lockout is a feature of Brute Force Detection, it doesn't protect the account from exposing his/hers credentials. Once the account is locked, the malicious actor can keep trying to login and will get informed the account is disabled once the password is correct.
https://issues.redhat.com/browse/KEYCLOAK-17835
— Red Hat
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-3513?
CVE-2021-3513 is a vulnerability in Keycloak that allows for a brute force attack even when the permanent lockout feature is enabled.
What is the severity of CVE-2021-3513?
The severity of CVE-2021-3513 is high.
How does CVE-2021-3513 impact confidentiality?
CVE-2021-3513 poses a threat to confidentiality.
What is the remedy for CVE-2021-3513 in Keycloak 13.0.0?
The remedy for CVE-2021-3513 in Keycloak 13.0.0 is to upgrade to version 13.0.1 or later.
What is the remedy for CVE-2021-3513 in RH-SSO7 Keycloak?
The remedy for CVE-2021-3513 in RH-SSO7 Keycloak is to upgrade to version 9.0.16 or later on EL6, EL7, or EL8.