VDB
Sign up
LOW2.7

GHSA-c25h-c27q-5qpv

Keycloak leaks configured LDAP bind credentials through the Keycloak admin console

Quick fix

GHSA-c25h-c27q-5qpv — org.keycloak:keycloak-ldap-federation: upgrade to the fixed version with the command below.

# pom.xml: bump <version>25.0.1</version> for org.keycloak:keycloak-ldap-federation

Details

### Impact

The LDAP testing endpoint allows to change the Connection URL independently of and without having to re-enter the currently configured LDAP bind credentials. An attacker with admin access (permission manage-realm) can change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console/compromised a user with sufficient privileges can leak domain credentials and can now attack the domain.

### Acknowledgements

Special thanks to Simon Wessling for reporting this issue and helping us improve our project

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-ldap-federation
Introduced in: 25.0.0Fixed in: 25.0.1
Fix# pom.xml: bump <version>25.0.1</version> for org.keycloak:keycloak-ldap-federation
Maven/org.keycloak:keycloak-ldap-federation
Introduced in: 0Fixed in: 22.0.12
Fix# pom.xml: bump <version>22.0.12</version> for org.keycloak:keycloak-ldap-federation
Maven/org.keycloak:keycloak-ldap-federation
Introduced in: 23.0.0Fixed in: 24.0.6
Fix# pom.xml: bump <version>24.0.6</version> for org.keycloak:keycloak-ldap-federation

References