CVE-2025-0604 Details
Description
A flaw was found in Keycloak. When an Active Directory user resets their password, the system updates it without performing an LDAP bind to validate the new credentials against AD. This vulnerability allows users whose AD accounts are expired or disabled to regain access in Keycloak, bypassing AD restrictions. The issue enables authentication bypass and could allow unauthorized access under certain conditions.
An authentication bypass vulnerability has been identified in Keycloak. When an Active Directory (AD) user resets their password, Keycloak updates the password without validating the new credentials through an LDAP bind. This oversight allows users with expired or disabled AD accounts to regain access in Keycloak, circumventing AD restrictions. The vulnerability could lead to unauthorized access under certain conditions.
Users can upgrade to the Red Hat build of Keycloak 26.0.10, which addresses this vulnerability. Instructions for applying the update are available on the Red Hat Customer Portal.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 22, 2025CISA-ADP
Assessed Jan 22, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2025:2544 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/errata/RHSA-2025:2545 | [email protected] | AdvisoryBundleRemedyVendor |
| https://access.redhat.com/security/cve/CVE-2025-0604 | [email protected] | AdvisoryRemedyVendor |
| https://bugzilla.redhat.com/show_bug.cgi?id=2338993 | [email protected] | Issue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Red Hat build of Keycloak | < 22 < 26.0 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 21, 2026 | CVE Modified | [email protected] |
| Aug 31, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Aug 4, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 10, 2025 | CVE Modified | [email protected] |
| Mar 10, 2025 | CVE Modified | [email protected] |
| Jan 22, 2025 | New CVE Received | [email protected] |
Volerion