Details of issue NIXPKGS-2025-0019
affected
created 26 Sep 2025
NIXPKGS-2025-0019
A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.
Vulnerabilities
Related packages
pkgs.keycloak
pkgs.terraform-providers.keycloak
pkgs.python311Packages.python-keycloak
pkgs.python312Packages.python-keycloak
pkgs.python313Packages.python-keycloak
pkgs.python312Packages.python-keycloak.x86_64-linux
Provides access to the Keycloak API
-
nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-linux
Provides access to the Keycloak API
-
nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.x86_64-darwin
Provides access to the Keycloak API
-
nixos-unstable 4.0.0
pkgs.python312Packages.python-keycloak.aarch64-darwin
Provides access to the Keycloak API
-
nixos-unstable 4.0.0