You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Keycloak vulnerable to LDAP Injection on UsernameForm Login
Low severity
GitHub Reviewed
Published
Nov 29, 2023
in
keycloak/keycloak
•
Updated Nov 30, 2023
A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.
References