Vulnerability Details CVE-2019-14909
A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP anonymous bind), any password, invalid or valid will be accepted.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 52.2%
CVSS Severity
CVSS v3 Score 9.3
CVSS v2 Score 7.5
Products affected by CVE-2019-14909
-
cpe:2.3:a:redhat:keycloak:7.0.0
-
cpe:2.3:a:redhat:keycloak:7.0.1