CVE-2019-14909

Description

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

Risk Information

Base Score
8.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS Score
Exploitation Probability
0.29

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2019-14909,CVE-2019-14910 are affected in Keycloak - keycloak-parent 7.0.1Windows
Vulnerabilities CVE-2019-14909,CVE-2019-14910 are affected in Keycloak - keycloak-parent for Linux 7.0.1Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234