A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm administrator to trigger deserialization of untrusted Java objects via a malicious LDAP server configuration.
https://access.redhat.com/errata/RHSA-2025:22091
https://access.redhat.com/errata/RHSA-2025:22090
https://access.redhat.com/errata/RHSA-2025:22089
https://access.redhat.com/errata/RHSA-2025:22088
https://bugzilla.redhat.com/show_bug.cgi?id=2416038
https://access.redhat.com/security/cve/CVE-2025-13467
Source: Mitre, NVD
Published: 2025-11-25
Updated: 2025-11-25
Base Score: 4.7
Vector: CVSS2#AV:N/AC:L/Au:M/C:P/I:P/A:N
Severity: Medium
Base Score: 5.5
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N
EPSS: 0.00042