Red Hat build of Keycloak
cpe:2.3:a:redhat:build_of_keycloak:*:*:*:*:*:*:*
- < 22
- < 26.0
An authentication bypass vulnerability has been identified in Keycloak. When an Active Directory (AD) user resets their password, Keycloak updates the password without validating the new credentials through an LDAP bind. This oversight allows users with expired or disabled AD accounts to regain access in Keycloak, circumventing AD restrictions. The vulnerability could lead to unauthorized access under certain conditions.
Exploitation of this vulnerability allows for authentication bypass, potentially leading to unauthorized access in Keycloak.
Users can upgrade to the Red Hat build of Keycloak 26.0.10, which addresses this vulnerability. Instructions for applying the update are available on the Red Hat Customer Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.