Back

CRITICAL

Keycloak: LDAP authentication accepts invalid passwords when using StartTLS

Published Dec 5, 2019

Description

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

Affected products

Remediation

Red Hat statement

This flaw does not affect Red Hat's Single Sign On (RHSSO) product and, thus, no patch will be forthcoming.

Red Hat mitigation

Disabling STARTTLS will fix the authentication flaw but leave the connection to the LDAP server unencrypted. Utilizing LDAPS will add a layer of encryption back to the LDAP connection but only at the SSLv3 level which also poses problems in and of itself.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 5, 2019
Updated Aug 5, 2024
Reserved Aug 10, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 3, 2019
GHSA-JF86-9434-F8C2