Skip to content

Commit

Permalink
Merge pull request #5108 from Chetven/GHSA-xmmm-jw76-q7vg
Browse files Browse the repository at this point in the history
  • Loading branch information
advisory-database[bot] authored Dec 20, 2024
2 parents a26e490 + 4ed4682 commit bf45b89
Showing 1 changed file with 4 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,9 @@
"id": "GHSA-xmmm-jw76-q7vg",
"modified": "2024-10-14T20:56:43Z",
"published": "2024-10-14T20:56:43Z",
"aliases": [],
"aliases": [
"CVE-2024-7318"
],
"summary": "One Time Passcode (OTP) is valid longer than expiration timeSeverity",
"details": "A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.",
"severity": [
Expand Down Expand Up @@ -71,4 +73,4 @@
"github_reviewed_at": "2024-10-14T20:56:43Z",
"nvd_published_at": null
}
}
}

0 comments on commit bf45b89

Please sign in to comment.