Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-8hc5-rmgf-qx6p: Keycloak vulnerable to LDAP Injection on UsernameForm Login

A flaw was found in the Keycloak package. This flaw allows an attacker to benefit from an LDAP query and access existing usernames in the server.

ghsa
#git#ldap

Keycloak vulnerable to LDAP Injection on UsernameForm Login

Low severity GitHub Reviewed Published Nov 29, 2023 in keycloak/keycloak • Updated Nov 29, 2023

ghsa: Latest News

GHSA-f679-254h-qhvj: Leantime allows Cross-Site Scripting (XSS)