Back

MEDIUM

Keycloak-ldap-federation: authentication bypass due to missing ldap bind after password reset in keycloak

Published Jan 22, 2025

Description

A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD restrictions. The issue enables authentication bypass and could allow unauthorized access under certain conditions.

Affected products

Remediation

No remediation recorded yet.

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Jan 22, 2025
Updated Sep 21, 2026
Reserved Jan 20, 2025
CISA Vulnrichment
Updated Jan 22, 2025
NVD
Status Deferred
Modified Sep 21, 2026
Red Hat
Severity Moderate
Public date Jan 20, 2025
ENISA EUVD
Assigner redhat
Published Jan 22, 2025
Updated Sep 21, 2026
Exploited since n/a
EUVD-2025-0178 GHSA-2P82-5WWR-43CW