CVE-2025-13467 - Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation

CVE ID : CVE-2025-13467
Published : Nov. 25, 2025, 4:02 p.m. | 16 minutes ago
Description : A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
Severity: 5.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/1hwUuZ2

Post a Comment

Previous Post Next Post