Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3910

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

Отчет

Within regulated environments, a combination of the following controls acts as a significant barrier to successfully exploiting a CWE-287: Improper Authentication vulnerability and therefore downgrades the severity of this particular CVE from Moderate to Low. Access to the platform is granted only after successful authentication through multifactor authentication (MFA). Domain accounts are configured to lock out based on predefined access policies reducing the effectiveness of brute-force attacks on authentication mechanisms. The platform employs IAM roles for identification and authentication within its cloud infrastructure that govern user access to resources and manage provisioning, deployment, and configuration within the platform environment. This reduces the risk of unauthorized access through third-party or external user accounts. Finally, memory protection mechanisms are used to enhance resilience against unauthorized commands or improper authentication.

Меры по смягчению последствий

No current mitigations are available for this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2361923org.keycloak.authentication: Two factor authentication bypass

EPSS

Процентиль: 4%
0.00022
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
4 месяца назад

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

CVSS3: 5.4
debian
4 месяца назад

A flaw was found in Keycloak. The org.keycloak.authorization package m ...

CVSS3: 5.4
github
4 месяца назад

Keycloak vulnerable to two factor authentication bypass

EPSS

Процентиль: 4%
0.00022
Низкий

5.4 Medium

CVSS3