First published: Fri Nov 29 2019(Updated: )
A bug exists in Keycloak 7.x where the user federation LDAP bind type is "none" (LDAP anonymous bind), any password, invalid or valid will be accepted Mitigation: If the LDAP service supports "simple" use that method instead
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Keycloak | =7.0.0 | |
Redhat Keycloak | =7.0.1 |
Use bindType:Simple
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-14909.
The severity of CVE-2019-14909 is high.
The affected software for CVE-2019-14909 is Keycloak 7.x.
CVE-2019-14909 is a vulnerability in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
To fix CVE-2019-14909, it is recommended to update to a version of Keycloak that is not impacted by the vulnerability.