Lucene search

K
githubGitHub Advisory DatabaseGHSA-8HC5-RMGF-QX6P
HistoryNov 29, 2023 - 9:33 p.m.

Keycloak vulnerable to LDAP Injection on UsernameForm Login

2023-11-2921:33:07
CWE-90
GitHub Advisory Database
github.com
29
keycloak
ldap injection
usernameform
security flaw
usernames

AI Score

6.9

Confidence

Low

A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.

Affected configurations

Vulners
Node
org.keycloak\keycloakMatchservices
OR
org.keycloak\keycloakMatchcore

AI Score

6.9

Confidence

Low

Related for GHSA-8HC5-RMGF-QX6P