A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 25 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 25 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | org.keycloak.storage.ldap: Keycloak: Deserialization of Untrusted Data in LDAP User Federation | Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation |
| First Time appeared |
Redhat
Redhat build Keycloak |
|
| CPEs | cpe:/a:redhat:build_keycloak:26.2::el9 cpe:/a:redhat:build_keycloak:26.4::el9 |
|
| Vendors & Products |
Redhat
Redhat build Keycloak |
|
| References |
|
Thu, 20 Nov 2025 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration. | |
| Title | org.keycloak.storage.ldap: Keycloak: Deserialization of Untrusted Data in LDAP User Federation | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published: 2025-11-25T16:02:21.105Z
Updated: 2025-11-25T21:30:06.491Z
Reserved: 2025-11-20T03:12:40.336Z
Link: CVE-2025-13467
Updated: 2025-11-25T16:28:27.482Z
Status : Awaiting Analysis
Published: 2025-11-25T16:16:06.623
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-13467