CVE-2022-2232
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Nov 14, 2024
Updated: Nov 15, 2024
Summary
CVE-2022-2232 is a vulnerability affecting the Keycloak package. An attacker can exploit this flaw through LDAP injection, bypassing the username lookup feature. This potentially enables unauthorized access to protected resources or further malicious actions. The vulnerability could pose a significant risk to organizations using Keycloak for authentication and authorization, making it essential to apply the available patch promptly.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- IBM Corporation