Org.keycloak.protocol.services: keycloak hostname verification
Published Apr 29, 2025
8.2
HIGHCVSS 3.1
EPSS 0.46%
Description
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Affected products
No data.
No data.
No data.
Red Hat Build of Keycloak
keycloak
Fixed · RHSA-2025:4336
Red Hat build of Keycloak 26
n/a
Fixed · RHSA-2025:8690
Red Hat build of Keycloak 26.0
rhbk/keycloak-operator-bundle:26.0.11-2
Fixed · RHSA-2025:4335
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9-operator:26.0-13
Fixed · RHSA-2025:4335
Red Hat build of Keycloak 26.0
rhbk/keycloak-rhel9:26.0-12
Fixed · RHSA-2025:4335
Red Hat build of Keycloak 26.2
rhbk/keycloak-operator-bundle:26.2.5-1
Fixed · RHSA-2025:8672
Red Hat build of Keycloak 26.2
rhbk/keycloak-rhel9-operator:26.2-4
Fixed · RHSA-2025:8672
Red Hat build of Keycloak 26.2
rhbk/keycloak-rhel9:26.2-4
Fixed · RHSA-2025:8672
Red Hat Single Sign-On 7
rh-sso7-keycloak
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Keycloak | keycloak | Fixed | RHSA-2025:4336 |
| Red Hat build of Keycloak 26 | n/a | Fixed | RHSA-2025:8690 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-operator-bundle:26.0.11-2 | Fixed | RHSA-2025:4335 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9-operator:26.0-13 | Fixed | RHSA-2025:4335 |
| Red Hat build of Keycloak 26.0 | rhbk/keycloak-rhel9:26.0-12 | Fixed | RHSA-2025:4335 |
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-operator-bundle:26.2.5-1 | Fixed | RHSA-2025:8672 |
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-rhel9-operator:26.2-4 | Fixed | RHSA-2025:8672 |
| Red Hat build of Keycloak 26.2 | rhbk/keycloak-rhel9:26.2-4 | Fixed | RHSA-2025:8672 |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Not affected | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".
Red Hat statement
Red Hat has rated this as an Important severity, although this configuration is not recommended, especially in production environments.
Red Hat mitigation
Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".
References (13)
- https://access.redhat.com/errata/RHSA-2025:4335 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:4336 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:8672 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:8690 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-3501 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2358834 issue-trackingx_refsource_REDHATIssue Tracking
- https://github.com/advisories/GHSA-hw58-3793-42gg Advisory
- https://github.com/keycloak/keycloak/commit/99ca24c832729075e04d8bc58666089268314272
- https://github.com/keycloak/keycloak/issues/39350
- https://github.com/keycloak/keycloak/pull/39366
- https://github.com/keycloak/keycloak/security/advisories/GHSA-hw58-3793-42gg
- https://nvd.nist.gov/vuln/detail/CVE-2025-3501
- https://www.cve.org/CVERecord?id=CVE-2025-3501
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:4335 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:4336 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:8672 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/errata/RHSA-2025:8690 | vendor-advisoryx_refsource_REDHAT | |
| https://access.redhat.com/security/cve/CVE-2025-3501 | vdb-entryx_refsource_REDHATVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2358834 | issue-trackingx_refsource_REDHATIssue Tracking | |
| https://github.com/advisories/GHSA-hw58-3793-42gg | Advisory | |
| https://github.com/keycloak/keycloak/commit/99ca24c832729075e04d8bc58666089268314272 | ||
| https://github.com/keycloak/keycloak/issues/39350 | ||
| https://github.com/keycloak/keycloak/pull/39366 | ||
| https://github.com/keycloak/keycloak/security/advisories/GHSA-hw58-3793-42gg | ||
| https://nvd.nist.gov/vuln/detail/CVE-2025-3501 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-3501 |
Change history (0)
No recorded changes yet.