CVE-2025-13467: Org.keycloak.storage.ldap: keycloak: deserialization of untrusted data in ldap user federation
A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13467?
CVE-2025-13467 is considered a high severity vulnerability due to the potential for exploitation through untrusted Java object deserialization.
How do I fix CVE-2025-13467?
To fix CVE-2025-13467, ensure that your Keycloak LDAP User Federation provider is updated to the latest version that addresses this vulnerability.
Who is affected by CVE-2025-13467?
CVE-2025-13467 affects systems using Keycloak LDAP User Federation with an authenticated realm administrator accessing a malicious LDAP server.
What type of attack can exploit CVE-2025-13467?
CVE-2025-13467 can be exploited through deserialization attacks via a compromised LDAP server configuration.
Is CVE-2025-13467 a remote or local vulnerability?
CVE-2025-13467 is primarily a local vulnerability that requires authenticated access to exploit.