Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-3910

Опубликовано: 29 апр. 2025
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

Меры по смягчению последствий

No current mitigations are available for this vulnerability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=2361923org.keycloak.authentication: Two factor authentication bypass

EPSS

Процентиль: 36%
0.00424
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 1 года назад

A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.

CVSS3: 5.4
debian
больше 1 года назад

A flaw was found in Keycloak. The org.keycloak.authorization package m ...

CVSS3: 5.4
github
больше 1 года назад

Keycloak vulnerable to two factor authentication bypass

EPSS

Процентиль: 36%
0.00424
Низкий

5.4 Medium

CVSS3