Impact
The Device Authorization Grant flow in Keycloak fails to verify whether a user account is currently locked due to brute‑force protection when redeeming a device access token. An attacker who already holds a valid session for a locked account can redeem a device code and obtain new security tokens, thereby maintaining continued access to the account even though it is meant to be temporarily disabled. This flaw enables unauthorized access to user resources and undermines the effectiveness of brute‑force safeguards, representing a moderate security risk.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. Specific version numbers are not disclosed in the available data, so the issue is presumed to impact all current supported releases of these products.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The exploit requires the attacker to possess an active session for the locked account, after which the attacker can complete the device login process and be issued valid tokens. While the necessary conditions are non‑zero, the absence of public exploitation data suggests a limited immediate risk, yet the potential for continued unauthorized access warrants prompt patching.
OpenCVE Enrichment