Launch Week Day 1: Announcing Security Design Review
HIGH 8.3 Maven

Keycloak Authentication Error

GHSA-fv4q-wm8c-wjg4 · CVE-2019-14909

Published · Modified

Description

A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.

Ready to move

Start Securing

Free, no credit card | First findings in minutes