Back

HIGH

Org.keycloak.protocol.services: keycloak hostname verification

Published Apr 29, 2025

Description

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.

Affected products

Remediation

Vendor solution

Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

Red Hat statement

Red Hat has rated this as an Important severity, although this configuration is not recommended, especially in production environments.

Red Hat mitigation

Use the correct TLS configuration and avoid using "--tls-hostname-verifier=any".

Weaknesses (1)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 29, 2025
Updated Sep 21, 2026
Reserved Apr 10, 2025
CISA Vulnrichment
Updated Apr 30, 2025
NVD
Status Deferred
Modified Sep 21, 2026
Red Hat
Severity Important
Public date Apr 29, 2025
GHSA-HW58-3793-42GG