{"id":"CVE-2018-14657","aliases":["GHSA-85v8-vx4w-q684"],"url":"https://o3.security/vulnerability/CVE-2018-14657","summary":"Keycloak Improper Bruteforce Detection","details":"A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.","published":"2018-11-13T19:29:00.337Z","modified":"2026-08-07T11:31:04.610966520Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-parent","fixedVersion":"4.6.0.Final"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3592"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3593"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:3595"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14657"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:04.610966520Z"}}