Lucene search

K
redhatcveRedhat.comRH:CVE-2022-2232
HistoryFeb 08, 2024 - 12:31 p.m.

CVE-2022-2232

2024-02-0812:31:54
redhat.com
access.redhat.com
14
keycloak
ldap injection
username bypass

AI Score

7.3

Confidence

Low

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

Mitigation

This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.

AI Score

7.3

Confidence

Low

Related for RH:CVE-2022-2232