CVE-2024-5967: Red Hat Build Of Keycloak
Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.
A vulnerability was found in Keycloak. The LDAP testing endpoint allows changing the Connection URL independently without re-entering the currently configured LDAP bind credentials. This flaw allows an attacker with admin access (permission manage-realm) to change the LDAP host URL ("Connection URL") to a machine they control. The Keycloak server will connect to the attacker's host and try to authenticate with the configured credentials, thus leaking them to the attacker. As a consequence, an attacker who has compromised the admin console or compromised a user with sufficient privileges can leak domain credentials and attack the domain.
Affected products
- Red Hat Red Hat Build Of Keycloak
- Red Hat Red Hat Build Of Keycloak 22: before 22.0.12-1 (fixed in 22.0.12-1); before 22-17 (fixed in 22-17); before 22-20 (fixed in 22-20)
- Red Hat Red Hat Single Sign-On 7
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 7: before 0:18.0.16-1.redhat_00001.1.el7sso (fixed in 0:18.0.16-1.redhat_00001.1.el7sso)
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 8: before 0:18.0.16-1.redhat_00001.1.el8sso (fixed in 0:18.0.16-1.redhat_00001.1.el8sso)
- Red Hat Red Hat Single Sign-On 7.6 For Rhel 9: before 0:18.0.16-1.redhat_00001.1.el9sso (fixed in 0:18.0.16-1.redhat_00001.1.el9sso)
- Red Hat Rhel-8 Based Middleware Containers: before 7.6-52 (fixed in 7.6-52)
Published 2024-06-18. Last modified 2026-06-17.