A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-2922 A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Github GHSA Github GHSA GHSA-8hc5-rmgf-qx6p Keycloak vulnerable to LDAP Injection on UsernameForm Login
Fixes

Solution

No solution given by the vendor.


Workaround

This flaw requires a misconfiguration of the "UUID LDAP Attribute" values. When they are set to the standard entryUUID, objectGUID or nsuniqueid Keycloak is not vulnerable.

History

Thu, 14 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 15:00:00 +0000

Type Values Removed Values Added
Title keycloak: LDAP injection on username input Keycloak: ldap injection on username input
CPEs cpe:/a:redhat:red_hat_single_sign_on:7
References

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-11-14T17:06:46.384Z

Reserved: 2022-06-27T19:32:32.993Z

Link: CVE-2022-2232

cve-icon Vulnrichment

Updated: 2024-11-14T17:06:42.583Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-14T15:15:06.527

Modified: 2024-11-15T13:58:08.913

Link: CVE-2022-2232

cve-icon Redhat

Severity : Low

Publid Date: 2023-11-29T00:00:00Z

Links: CVE-2022-2232 - Bugzilla

cve-icon OpenCVE Enrichment

No data.