Authentication mechanism absence or evasion In org.keycloak:keycloak-parent
Description
Keycloak Authentication Error A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 8.0.0 | ||
npm | 8.0.0 |
Aliases
1. 2. 3. 4. 5. 6.
References
1.