Keycloak: ldap injection on username input
Published Nov 14, 2024
7.5
HIGHCVSS 3.1
EPSS 0.65%
Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Single Sign-On 7 | affected |
|
No data.
No data.
Red Hat Single Sign-On 7
rh-sso7-keycloak
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.
Red Hat mitigation
This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.
References (11)
- https://access.redhat.com/errata/RHSA-2024:0094 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0095 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2024:0096 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2022-2232 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2096994 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2922 Advisory
- https://github.com/advisories/GHSA-8hc5-rmgf-qx6p Advisory
- https://github.com/keycloak/keycloak/commit/4252e394cf725b16f7e4e19aa32b03fd3fe13fde
- https://github.com/keycloak/keycloak/security/advisories/GHSA-8hc5-rmgf-qx6p
- https://nvd.nist.gov/vuln/detail/CVE-2022-2232
- https://www.cve.org/CVERecord?id=CVE-2022-2232
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2024:0094 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:0095 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2024:0096 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2022-2232 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2096994 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-2922 | Advisory | |
| https://github.com/advisories/GHSA-8hc5-rmgf-qx6p | Advisory | |
| https://github.com/keycloak/keycloak/commit/4252e394cf725b16f7e4e19aa32b03fd3fe13fde | ||
| https://github.com/keycloak/keycloak/security/advisories/GHSA-8hc5-rmgf-qx6p | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-2232 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-2232 |
Change history (0)
No recorded changes yet.