CVE-2024-1722 Overview
CVE-2024-1722 is a flaw in Red Hat Keycloak that allows a remote unauthenticated attacker to block legitimate users from logging in. The issue affects Keycloak version 23.0.5 and stems from improper handling of failed authentication attempts, which triggers account lockout on targeted accounts. The vulnerability maps to CWE-645 (Overly Restrictive Account Lockout Mechanism). Exploitation impacts availability only; confidentiality and integrity are not affected.
Critical Impact
An unauthenticated attacker on the network can lock out arbitrary user accounts, producing a targeted denial-of-service condition against Keycloak-protected applications.
Affected Products
- Red Hat Keycloak 23.0.5
- Red Hat Single Sign-On distributions built on the affected Keycloak release
- Applications relying on the affected Keycloak instance as their identity provider
Discovery Timeline
- 2024-02-29 - CVE-2024-1722 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2024-1722
Vulnerability Analysis
Keycloak enforces a brute-force protection policy that temporarily disables an account after a configurable number of failed logins. CVE-2024-1722 abuses this protection. An unauthenticated attacker submits repeated invalid authentication attempts against a known username, exceeding the failure threshold and forcing Keycloak to lock the account. The legitimate account owner is then unable to authenticate until the lockout window expires or an administrator intervenes.
The vulnerability affects availability only. It does not disclose credentials, bypass authentication, or grant access to protected resources. The impact scales with the attacker's ability to enumerate or guess valid usernames.
Root Cause
The root cause is the account lockout policy triggering on unauthenticated failed attempts without differentiating between attacker-driven and user-driven failures. Keycloak's brute-force detector, designed to defeat password guessing, becomes a tool for denial of service when the same mechanism can be invoked by any remote party against any known account.
Attack Vector
The attack is remote and requires no privileges or user interaction. An attacker sends repeated failed login requests against the Keycloak authentication endpoint targeting a specific username. Once Keycloak records enough failures for that account, subsequent legitimate logins are rejected. Attackers can automate the request pattern across many accounts to broaden the impact. See the Red Hat CVE-2024-1722 Advisory and Red Hat Bug Report #2265389 for vendor analysis.
Detection Methods for CVE-2024-1722
Indicators of Compromise
- Spikes in LOGIN_ERROR events in the Keycloak event log tied to a small set of usernames and originating from one or a few source IPs.
- Increased USER_DISABLED_BY_PERMANENT_LOCKOUT or USER_TEMPORARILY_DISABLED events across unrelated user accounts within a short time window.
- Help desk tickets from multiple users reporting simultaneous account lockouts without prior password changes.
Detection Strategies
- Correlate authentication failure events by target username and source IP to identify one-to-many lockout patterns.
- Alert on Keycloak admin events indicating rapid growth in temporarily disabled accounts.
- Baseline normal failed-login volume per realm and flag deviations that exceed statistical thresholds.
Monitoring Recommendations
- Forward Keycloak event and admin event logs to a centralized SIEM for retention and correlation.
- Monitor rate of failed logins against the /realms/{realm}/protocol/openid-connect/token and login form endpoints.
- Track the count of disabled or temporarily locked users as a health metric and alert on abnormal growth.
How to Mitigate CVE-2024-1722
Immediate Actions Required
- Upgrade Keycloak to a fixed release per the Red Hat CVE-2024-1722 Advisory.
- Review brute-force detection settings in each realm and reduce exposure of usernames to unauthenticated clients.
- Place Keycloak login endpoints behind a web application firewall or rate-limiting reverse proxy.
Patch Information
Red Hat provides fixes and mitigation guidance in the Red Hat CVE-2024-1722 Advisory. Administrators running Keycloak 23.0.5 should apply the vendor-supplied update for their distribution. Additional technical context is available in Red Hat Bug Report #2265389.
Workarounds
- Configure Keycloak brute-force protection to use short temporary lockouts rather than permanent lockouts, reducing the duration of any induced denial of service.
- Restrict access to the Keycloak authentication endpoints by source network where feasible, or require an upstream challenge such as CAPTCHA or bot management.
- Enable per-IP rate limiting at the reverse proxy layer to blunt automated failed-login floods against known usernames.
# Configuration example: reduce lockout duration and enable quick recovery
# keycloak realm brute-force settings (via kcadm.sh)
kcadm.sh update realms/myrealm \
-s bruteForceProtected=true \
-s permanentLockout=false \
-s maxFailureWaitSeconds=60 \
-s waitIncrementSeconds=30 \
-s failureFactor=10
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.