CVE-2019-14909
published 2019-12-04CVE-2019-14909: A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be…
PriorityP337high8.3CVSS 3.1
AVNACLPRNUINSCCLILAL
EPSS
1.08%
61.3th percentile
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
| redhat | keycloak | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
nvdv3.09.3CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Keycloak Authentication Error
osv·2022-05-24
CVE-2019-14909 [HIGH] Keycloak Authentication Error
Keycloak Authentication Error
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
GHSA
Keycloak Authentication Error
ghsa·2022-05-24
CVE-2019-14909 [HIGH] CWE-287 Keycloak Authentication Error
Keycloak Authentication Error
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Red Hat
Keycloak: LDAP authentication accepts invalid passwords with bindType none
vendor_redhat·2019-12-03·CVSS 8.3
CVE-2019-14909 [HIGH] CWE-306 Keycloak: LDAP authentication accepts invalid passwords with bindType none
Keycloak: LDAP authentication accepts invalid passwords with bindType none
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
A flaw was found in Keycloak version 7.x (community-only), where the user federation LDAP bind type is none (LDAP anonymous bind). This flaw allows any password, invalid or valid, to be accepted.
Mitigation: Use bindType:Simple
Package: rh-sso7-keycloak (Red Hat Single Sign-On 7) - Not affected
No detection rules found.
No public exploits indexed.
2019-12-04
Published