Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Remediation
References
https://access.redhat.com/errata/RHSA-2024:0094
https://access.redhat.com/errata/RHSA-2024:0095
https://access.redhat.com/errata/RHSA-2024:0096
https://access.redhat.com/security/cve/CVE-2022-2232
https://bugzilla.redhat.com/show_bug.cgi?id=2096994
Related Vulnerabilities
CVE-2011-2093 Vulnerability in maven package com.adobe.blazeds:blazeds-core
CVE-2016-10544 Vulnerability in npm package uws
CVE-2017-1000397 Vulnerability in maven package org.jenkins-ci.main:maven-plugin
CVE-2011-2526 Vulnerability in maven package tomcat:catalina
CVE-2016-10703 Vulnerability in maven package org.webjars.npm:ecstatic