Skip to content

Commit 28fe1b4

Browse files
1 parent 4966d00 commit 28fe1b4

File tree

1 file changed

+5
-6
lines changed

1 file changed

+5
-6
lines changed

advisories/github-reviewed/2025/11/GHSA-93vm-mqpw-8wh3/GHSA-93vm-mqpw-8wh3.json

Lines changed: 5 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,12 @@
11
{
22
"schema_version": "1.4.0",
33
"id": "GHSA-93vm-mqpw-8wh3",
4-
"modified": "2025-11-26T22:01:36Z",
4+
"modified": "2025-12-19T21:27:08Z",
55
"published": "2025-11-25T18:32:22Z",
6-
"aliases": [
7-
"CVE-2025-13467"
8-
],
9-
"summary": "Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization",
10-
"details": "A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.",
6+
"withdrawn": "2025-12-19T21:27:08Z",
7+
"aliases": [],
8+
"summary": "Duplicate Advisory: Keycloak LDAP User Federation provider enables admin-triggered untrusted Java deserialization",
9+
"details": "### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-4hx9-48xh-5mxr. This link is maintained to preserve external references.\n\n### Original Description\n\nA flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.",
1110
"severity": [
1211
{
1312
"type": "CVSS_V3",

0 commit comments

Comments
 (0)