CVE-2024-1722

    Dashboard / Vulnerabilities / CVE-2024-1722

    CVE-2024-1722

    Published: 27 Feb 2024Last Modified: 12 Aug 2026

    Summary: Keycloak-core: dos via account lockout

    Details: A flaw was found in Keycloak. In certain conditions, this issue may allow a remote unauthenticated attacker to block other accounts from logging in.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 17ea0ea501bdd0743a1f44a93a84b66922236918
    Fixed -None

    Affected versions

    23.0.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2024-1722 | CVE-DB