Keycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloak
Published Jan 22, 2025
5.4
MEDIUMCVSS 3.1
EPSS 0.59%
Description
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD restrictions. The issue enables authentication bypass and could allow unauthorized access under certain conditions.
Affected products
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||
|---|---|---|---|---|---|---|
| Red Hat | Red Hat Single Sign-On 7 | affected |
|
No data.
No data.
Red Hat Build of Keycloak
n/a
Fixed · RHSA-2025:2545
Red Hat build of Keycloak 26.0
rhbk/keycloak-operator-bundle:26.0.10-3
Fixed · RHSA-2025:2544
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9-operator:26.0-12
Fixed · RHSA-2025:2544
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9:26.0-11
Fixed · RHSA-2025:2544
Red Hat Single Sign-On 7
keycloak-ldap-federation
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Keycloak | n/a | Fixed | RHSA-2025:2545 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-operator-bundle:26.0.10-3 | Fixed | RHSA-2025:2544 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9-operator:26.0-12 | Fixed | RHSA-2025:2544 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9:26.0-11 | Fixed | RHSA-2025:2544 |
| Red Hat Single Sign-On 7 | keycloak-ldap-federation | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/errata/RHSA-2025:2544 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:2545 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-0604 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2338993 issue-trackingx_refsource_REDHATIssue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-0178 Advisory
- https://github.com/advisories/GHSA-2p82-5wwr-43cw Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-2p82-5wwr-43cw
- https://nvd.nist.gov/vuln/detail/CVE-2025-0604
- https://www.cve.org/CVERecord?id=CVE-2025-0604
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:2544 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:2545 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2025-0604 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2338993 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-0178 | Advisory | |
| https://github.com/advisories/GHSA-2p82-5wwr-43cw | Advisory | |
| https://github.com/keycloak/keycloak/security/advisories/GHSA-2p82-5wwr-43cw | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-0604 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-0604 |
Change history (0)
No recorded changes yet.