A flaw was found in Keycloak 4.2.1.Final, 4.3.0.Final. When TOPT enabled, an improper implementation of the Brute Force detection algorithm will not enforce its protection measures.
This issue has been addressed in the following products: Red Hat Single Sign-On 7.2 for RHEL 6 Via RHSA-2018:3592 https://access.redhat.com/errata/RHSA-2018:3592
This issue has been addressed in the following products: Red Hat Single Sign-On 7.2 for RHEL 7 Via RHSA-2018:3593 https://access.redhat.com/errata/RHSA-2018:3593
This issue has been addressed in the following products: Red Hat Single Sign-On 7.2.5 zip Via RHSA-2018:3595 https://access.redhat.com/errata/RHSA-2018:3595
This vulnerability is out of security support scope for the following product: * Red Hat Mobile Application Platform Please refer to https://access.redhat.com/support/policy/updates/rhmap for more details