26.7.2
12 years ago
3 days ago
Known vulnerabilities in the org.keycloak:keycloak-ldap-federation package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Access Control Bypass in How to fix Access Control Bypass? Upgrade | [,26.4.14)[26.6.0,26.6.5)[26.7.0,26.7.1) |
Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input in the LDAP federation BER decoder. An attacker can cause the Java Virtual Machine to terminate and disrupt service availability by sending a malformed LDAP password-policy response during authentication. This is only exploitable if the LDAP user-storage provider is configured and the attacker has high privileges, such as a realm administrator or access to a compromised LDAP server. How to fix Improper Validation of Specified Quantity in Input? Upgrade | [26.6.0,26.6.3) |