Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Remediation
References
https://access.redhat.com/errata/RHSA-2024:0094
https://access.redhat.com/errata/RHSA-2024:0095
https://access.redhat.com/errata/RHSA-2024:0096
https://access.redhat.com/security/cve/CVE-2022-2232
https://bugzilla.redhat.com/show_bug.cgi?id=2096994
Related Vulnerabilities
CVE-2020-7740 Vulnerability in npm package node-pdf-generator
CVE-2023-32688 Vulnerability in npm package @parse/push-adapter
CVE-2015-9242 Vulnerability in maven package org.webjars.npm:ecstatic
CVE-2016-1000232 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2020-1727 Vulnerability in maven package org.keycloak:keycloak-services