Insecure deserialization In org.keycloak:keycloak-ldap-federation
Description
Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
Mitigation
Disable LDAP referrals in all LDAP user providers in all realms if projects cannot upgrade to the patched versions.
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 26.4.6, 26.2.11 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6.