{"id":"CVE-2019-14910","details":"A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation and StartTLS is used instead of SSL/TLS from the LDAP server (ldaps), in this case user authentication succeeds even if invalid password has entered.","aliases":["GHSA-jf86-9434-f8c2"],"modified":"2026-08-07T14:49:59.941513Z","published":"2019-12-05T15:15:11.157Z","references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14910"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keycloak/keycloak","events":[{"introduced":"e6a274ea0e31c6572e795f3372f006c88122539b"},{"last_affected":"7787e89db4a55a524351bb39d9f0106221c8765a"}],"database_specific":{"cpe":["cpe:2.3:a:redhat:keycloak:7.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:keycloak:7.0.1:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.0.0"},{"last_affected":"7.0.0"},{"introduced":"7.0.1"},{"last_affected":"7.0.1"}],"source":"CPE_STRING"}}],"versions":["7.0.0","7.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-14910.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}