Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.5 Maven

Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization

GHSA-4hx9-48xh-5mxr · CVE-2025-13467

Published · Modified

Description

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

Mitigation

Disable LDAP referrals in all LDAP user providers in all realms if projects cannot upgrade to the patched versions.

Ready to move

Start Securing

Free, no credit card | First findings in minutes