Back

HIGH

Keycloak: LDAP authentication accepts invalid passwords with bindType none

Published Dec 4, 2019

Description

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

Affected products

Remediation

Red Hat mitigation

Use bindType:Simple

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 4, 2019
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 3, 2019
GHSA-FV4Q-WM8C-WJG4