Improper authentication in Keycloak - CVE-2025-0604
Published: March 11, 2025
Vulnerability identifier: #VU105508
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-0604
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass authentication process.
The vulnerability exists due to Keycloak does not perform an LDAP bind after a password reset. A remote user can bypass authentication process for expired or disabled AD accounts gain unauthorized access to the application.
Affected software
Keycloak
Red Hat build of Keycloak
Red Hat build of Keycloak
How to mitigate CVE-2025-0604
Install updates from vendor's website.
Keycloak - addressed in versions 26.0.10, 26.1.3
Red Hat build of Keycloak - update to 26.0.10
Red Hat build of Keycloak - update to 26.0.10