A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 14 Nov 2024 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | keycloak: LDAP injection on username input | Keycloak: ldap injection on username input |
| CPEs | cpe:/a:redhat:red_hat_single_sign_on:7 | |
| References |
|
Status: PUBLISHED
Assigner: redhat
Published: 2024-11-14T14:51:14.594Z
Updated: 2024-11-14T17:06:46.384Z
Reserved: 2022-06-27T19:32:32.993Z
Link: CVE-2022-2232
Updated: 2024-11-14T17:06:42.583Z
Status : Awaiting Analysis
Published: 2024-11-14T15:15:06.527
Modified: 2024-11-15T13:58:08.913
Link: CVE-2022-2232