Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3501

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 8.2

Описание

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Отчет

Red Hat has rated this as an Important severity, although this configuration is not recommended, especially in production environments.

Меры по смягчению последствий

Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Single Sign-On 7keycloakNot affected
Red Hat Build of KeycloakkeycloakFixedRHSA-2025:433629.04.2025
Red Hat build of Keycloak 26FixedRHSA-2025:869009.06.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-operator-bundleFixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9FixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.0rhbk/keycloak-rhel9-operatorFixedRHSA-2025:433529.04.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-operator-bundleFixedRHSA-2025:867209.06.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9FixedRHSA-2025:867209.06.2025
Red Hat build of Keycloak 26.2rhbk/keycloak-rhel9-operatorFixedRHSA-2025:867209.06.2025

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-297
https://bugzilla.redhat.com/show_bug.cgi?id=2358834org.keycloak.protocol.services: Keycloak hostname verification

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
5 месяцев назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

CVSS3: 8.2
debian
5 месяцев назад

A flaw was found in Keycloak. By setting a verification policy to 'ALL ...

CVSS3: 8.2
github
5 месяцев назад

Keycloak hostname verification

8.2 High

CVSS3