A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions.
| Software | From | Fixed in |
|---|---|---|
org.keycloak / keycloak-ldap-federation
|
- | 23.0.1 |
org.keycloak / keycloak-services
|
- | 23.0.1 |