Early Access — Mondoo Vulnerability Intelligence is currently in preview.
Mondoo Vulnerability Intelligence
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
Search vulnerabilities and malicious packages across npm, PyPI, Go, GitHub Actions, VS Code, and more.
A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
Disable LDAP referrals in all LDAP user providers in all realms if projects cannot upgrade to the patched versions.
26.4.6Exploitability
AV:NAC:LPR:HUI:NScope
S:CImpact
C:LI:LA:NCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N