CVE-2024-7318
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.8
- CVSS vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.39%
- CWE
- CWE-324
- Published
- 2024-09-09
- Last modified
- 2026-03-13
Affected products
- Red Hat Red Hat build of Keycloak 24
- Red Hat Red Hat build of Keycloak 24
Weakness type
Related vulnerabilities
- CVE-2026-39923 — Flarum < 1.8.16 Password Reset Token Expiry Bypass via POST /reset
- CVE-2026-54787 — sigstore-go fails to check signature timestamps against a signing key's validity period
- CVE-2026-52809 — Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES
- CVE-2025-33012 — IBM Db2 improper account lockout
- CVE-2025-48813 — Virtual Secure Mode Spoofing Vulnerability
- CVE-2023-5342 — Shim: expired secure boot certificate
- CVE-2025-2291 — PgBouncer default auth_query does not take Postgres password expiry into account
- CVE-2025-31123 — Zitadel Expired JWT Keys Usable for Authorization Grants