Back

HIGH

Keycloak: ldap injection on username input

Published Nov 14, 2024

Description

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

Affected products

Remediation

Vendor solution

This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.

Red Hat mitigation

This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 14, 2024
Updated Nov 14, 2024
Reserved Jun 27, 2022
CISA Vulnrichment
Updated Nov 14, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 29, 2023
ENISA EUVD
Assigner redhat
Published Nov 14, 2024
Updated Nov 14, 2024
Exploited since n/a
EUVD-2023-2922 GHSA-8HC5-RMGF-QX6P