Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.keycloak/keycloak-ldap-federation
  4. ›
  5. CVE-2024-5967

CVE-2024-5967: Keycloak leaks configured LDAP bind credentials through the Keycloak admin console

June 21, 2024

The LDAP testing endpoint allows to change the Connection URL independently of and without having to re-enter the currently configured LDAP bind credentials. An attacker with admin access (permission manage-realm) can change the LDAP host URL (“Connection URL”) to a machine they control. The Keycloak server will connect to the attacker’s host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console/compromised a user with sufficient privileges can leak domain credentials and can now attack the domain.

References

  • access.redhat.com/security/cve/CVE-2024-5967
  • bugzilla.redhat.com/show_bug.cgi?id=2292200
  • github.com/advisories/GHSA-c25h-c27q-5qpv
  • github.com/keycloak/keycloak
  • github.com/keycloak/keycloak/security/advisories/GHSA-c25h-c27q-5qpv
  • nvd.nist.gov/vuln/detail/CVE-2024-5967

Code Behaviors & Features

Detect and mitigate CVE-2024-5967 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 22.0.12, all versions starting from 23.0.0 before 24.0.6, all versions starting from 25.0.0 before 25.0.1, version 25.0.0

Fixed versions

  • 25.0.1
  • 22.0.12
  • 24.0.6

Solution

Upgrade to versions 22.0.12, 24.0.6, 25.0.1 or above.

Impact 2.7 LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-276: Incorrect Default Permissions

Source file

maven/org.keycloak/keycloak-ldap-federation/CVE-2024-5967.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:58 +0000.