CVE-2020-1744

Source
https://cve.org/CVERecord?id=CVE-2020-1744
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1744.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-1744
Aliases
Downstream
Related
Published
2020-03-24T14:15:13.293Z
Modified
2026-03-23T05:12:36.307623Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A flaw was found in keycloak before version 9.0.1. When configuring an Conditional OTP Authentication Flow as a post login flow of an IDP, the failure login events for OTP are not being sent to the brute force protection event queue. So BruteForceProtector does not handle this events.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-1744.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "9.0.1"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "fixed": "9.0.1"
            }
        ]
    }
]