An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1qZjg2LTk0MzQtZjhjMs4AAi3L

Critical EPSS: 0.00436% (0.61695 Percentile) EPSS:

Keycloak Authentication Error

Affected Packages Affected Versions Fixed Versions
maven:org.keycloak:keycloak-parent >= 7.0.0, <= 7.0.1 No known fixed version
9 Dependent packages
41 Dependent repositories

Affected Version Ranges

All affected versions

7.0.0, 7.0.1

A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.

References: