Junglewise Threat Intelligence

Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

Severity: low · CVSS 3.1 · Published 2025-01-22

Technologies: org.keycloak:keycloak-ldap-federation (Maven). Vendors: Maven.

Executive brief

Duplicate Advisory: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

Affected products

  • Maven org.keycloak:keycloak-ldap-federation

Related threats