Keycloak, an open-source identity and access management solution, has been found to have several security issues, including OTP bypass vulnerabilities, unauthorized access to certain administrative functionalities, and race conditions in the anti-brute-force mechanism. These issues allow attackers to bypass multi-factor

7m read timeFrom security.humanativaspa.it
Post cover image
Table of contents
OTP bypassMultiple security issues in authentication and authorizationMultiple race conditions in anti-brute force mechanismSome final considerations

Sort: