CVE-2022-2232
EPSS 0.11%Keycloak vulnerable to LDAP Injection on UsernameForm Login
Published: 11/29/2023Modified: 12/4/2024
Description
A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.
Affected packages (2)
- Maven/org.keycloak:keycloak-ldap-federationfrom 0, < 23.0.1
- Maven/org.keycloak:keycloak-servicesfrom 0, < 23.0.1