CVE-2022-2232

HIGH

Keycloak LDAP Federation < 23.0.1 - LDAP Injection via Username Lookup

Title source: llm
STIX 2.1

Description

A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.

References (5)

Core 5
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2024:0094
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2024:0095
Vendor Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2024:0096
Vendor Advisory vdb-entry x_refsource_redhat
https://access.redhat.com/security/cve/CVE-2022-2232
Issue Tracking issue-tracking x_refsource_redhat
https://bugzilla.redhat.com/show_bug.cgi?id=2096994

Scores

CVSS v3 7.5
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (3)
org.keycloak/keycloak-ldap-federation 0 - 23.0.1Maven
org.keycloak/keycloak-services 0 - 23.0.1Maven
Red Hat/Red Hat Single Sign-On 7
Published Nov 14, 2024
Tracked Since Feb 18, 2026