AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-7318

MEDIUM · CVSS 4.8 EPSS 0.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-09-09 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 4.8. See the original NVD description below for full technical details.

CVE
CVE-2024-7318
Severity
MEDIUM
CVSS
4.8
EPSS
0.39%

Original NVD Description

A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around 30 seconds in, the tokens are valid for an additional 30 seconds totaling 1 minute. A one time passcode that is valid longer than its expiration time increases the attack window for malicious actors to abuse the system and compromise accounts. Additionally, it increases the attack surface because at any given time, two OTPs are valid.

Related CVEs

Other vulnerabilities affecting the same vendor(s)