A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2020-03-24T00:00:00
Updated: 2024-08-04T06:46:30.879Z
Reserved: 2019-11-27T00:00:00
Link: CVE-2020-1744
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-03-24T14:15:13.293
Modified: 2023-11-07T03:19:32.223
Link: CVE-2020-1744
Redhat