A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
https://github.com/advisories/GHSA-xv7h-95r7-595j
https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-6648