Authentication mechanism absence or evasion In org.keycloak:keycloak-ldap-federation
Description
Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak The issue arises because Keycloak does not perform an LDAP bind after a password reset, leading to potential authentication bypass for expired or disabled AD accounts. A fix should enforce LDAP validation after password updates to ensure consistency with AD authentication policies.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 26.1.3, 26.0.10 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2.