Description
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
Remediation
References
https://access.redhat.com/errata/RHSA-2024:0094
https://access.redhat.com/errata/RHSA-2024:0095
https://access.redhat.com/errata/RHSA-2024:0096
https://access.redhat.com/security/cve/CVE-2022-2232
https://bugzilla.redhat.com/show_bug.cgi?id=2096994
Related Vulnerabilities
CVE-2018-3719 Vulnerability in npm package mixin-deep
CVE-2016-6816 Vulnerability in maven package org.apache.tomcat:tomcat-coyote
CVE-2022-38900 Vulnerability in maven package org.webjars.npm:decode-uri-component
CVE-2012-5785 Vulnerability in maven package org.apache.axis2:axis2
CVE-2017-9791 Vulnerability in maven package org.apache.struts:struts2-struts1-plugin