CVE-2022-2232

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024

Summary

CVE-2022-2232 is a vulnerability affecting the Keycloak package. An attacker can exploit this flaw through LDAP injection, bypassing the username lookup feature. This potentially enables unauthorized access to protected resources or further malicious actions. The vulnerability could pose a significant risk to organizations using Keycloak for authentication and authorization, making it essential to apply the available patch promptly.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share