{"id":"CVE-2022-2232","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-2232","summary":"Keycloak vulnerable to LDAP Injection on UsernameForm Login","details":"A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.","published":"2023-11-29T21:33:07Z","modified":"2024-12-04T05:36:37.532782Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-ldap-federation","fixedVersion":"23.0.1"},{"ecosystem":"Maven","name":"org.keycloak:keycloak-services","fixedVersion":"23.0.1"}],"fix":{"url":"https://github.com/keycloak/keycloak/commit/4252e394cf725b16f7e4e19aa32b03fd3fe13fde","label":"keycloak/keycloak@4252e39"},"references":[{"type":"WEB","url":"https://github.com/keycloak/keycloak/security/advisories/GHSA-8hc5-rmgf-qx6p"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/commit/4252e394cf725b16f7e4e19aa32b03fd3fe13fde"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2024-12-04T05:36:37.532782Z"}}