org.keycloak:keycloak-ldap-federation@26.4.3 vulnerabilities

  • latest version

    26.4.5

  • first published

    11 years ago

  • latest version published

    16 days ago

  • licenses detected

  • package registry

  • Direct Vulnerabilities

    Known vulnerabilities in the org.keycloak:keycloak-ldap-federation package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Deserialization of Untrusted Data

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the URL references when following referrals. An attacker can manipulate application behavior by configuring a malicious LDAP server and triggering deserialization of untrusted Java objects as an authenticated realm administrator.

    Notes:

    • This vulnerability can potentially result in JDNI references being used in case custom extensions were written for the library.
    • The fix for this issue was also back-ported into 26.2.11 which has not been published to Maven Central.

    How to fix Deserialization of Untrusted Data?

    Upgrade org.keycloak:keycloak-ldap-federation to version 26.4.6 or higher.

    [,26.4.6)