CVE-2019-14909: Critical severity red hat keycloak vulnerability
A bug exists in Keycloak 7.x where the user federation LDAP bind type is "none" (LDAP anonymous bind), any password, invalid or valid will be accepted
Mitigation: If the LDAP service supports "simple" use that method instead
Other sources
A flaw was found in Keycloak version 7.x (community-only), where the user federation LDAP bind type is none (LDAP anonymous bind). This flaw allows any password, invalid or valid, to be accepted.
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Keycloak vulnerability?
The vulnerability ID is CVE-2019-14909.
What is the severity of CVE-2019-14909?
The severity of CVE-2019-14909 is high.
What is the affected software for CVE-2019-14909?
The affected software for CVE-2019-14909 is Keycloak 7.x.
What is the description of CVE-2019-14909?
CVE-2019-14909 is a vulnerability in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
How can I fix CVE-2019-14909?
To fix CVE-2019-14909, it is recommended to update to a version of Keycloak that is not impacted by the vulnerability.