CVE-2022-2232
EPSS 0.11%Keycloak vulnerable to LDAP Injection on UsernameForm Login
發布日:2023/11/29修改日:2024/12/4
描述
A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.
受影響套件(2)
- Maven/org.keycloak:keycloak-ldap-federationfrom 0, < 23.0.1
- Maven/org.keycloak:keycloak-servicesfrom 0, < 23.0.1