Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3501

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Отчет

Red Hat has rated this as an Important severity, although this configuration is not recommended, especially in production environments.

Меры по смягчению последствий

Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7rh-sso7-keycloakNot affected
Red Hat Build of KeycloakkeycloakFixedRHSA-2025:433629.04.2025
Red Hat build of Keycloak 26FixedRHSA-2025:869009.06.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-operator-bundleFixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9FixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9-operatorFixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-operator-bundleFixedRHSA-2025:867209.06.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9FixedRHSA-2025:867209.06.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9-operatorFixedRHSA-2025:867209.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=2358834org.keycloak.protocol.services: Keycloak hostname verification

EPSS

Процентиль: 37%
0.00439
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 1 года назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

CVSS3: 8.2
debian
больше 1 года назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL ...

CVSS3: 8.2
github
больше 1 года назад

Keycloak hostname verification

EPSS

Процентиль: 37%
0.00439
Низкий

8.2 High

CVSS3