PT-2025-54693 · Maven · Org.Keycloak:Keycloak-Ldap-Federation

Published

2025-11-25

·

Updated

2025-11-25

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-4hx9-48xh-5mxr. This link is maintained to preserve external references.

Original Description

A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-93VM-MQPW-8WH3

Affected Products

Org.Keycloak:Keycloak-Ldap-Federation