Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Remediation
References
https://access.redhat.com/errata/RHSA-2024:0094
https://access.redhat.com/errata/RHSA-2024:0095
https://access.redhat.com/errata/RHSA-2024:0096
https://access.redhat.com/security/cve/CVE-2022-2232
https://bugzilla.redhat.com/show_bug.cgi?id=2096994
Related Vulnerabilities
CVE-2021-29486 Vulnerability in npm package cumulative-distribution-function
CVE-2017-15697 Vulnerability in maven package org.apache.nifi:nifi-web-utils
CVE-2020-1757 Vulnerability in maven package io.undertow:undertow-servlet
CVE-2017-9801 Vulnerability in maven package org.apache.commons:commons-email
CVE-2020-14338 Vulnerability in maven package xerces:xercesimpl