Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Remediation
References
https://access.redhat.com/errata/RHSA-2024:0094
https://access.redhat.com/errata/RHSA-2024:0095
https://access.redhat.com/errata/RHSA-2024:0096
https://access.redhat.com/security/cve/CVE-2022-2232
https://bugzilla.redhat.com/show_bug.cgi?id=2096994
Related Vulnerabilities
CVE-2020-13961 Vulnerability in npm package strapi
CVE-2016-4438 Vulnerability in maven package org.apache.struts:struts2-rest-plugin
CVE-2016-10540 Vulnerability in npm package minimatch
CVE-2020-8125 Vulnerability in npm package klona
CVE-2017-1000401 Vulnerability in maven package org.jenkins-ci.main:jenkins-core