A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Keycloak | Redhat | 7.0.0 (including) | 7.0.0 (including) |
Keycloak | Redhat | 7.0.1 (including) | 7.0.1 (including) |