CVE-2025-3501

A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Configurations

No configuration.

History

02 May 2025, 13:53

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en Keycloak. Al configurar la política de verificación como "ALL", se omite la verificación del certificado del almacén de confianza, lo cual es involuntario.

30 Apr 2025, 03:15

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4336 -

29 Apr 2025, 23:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2025:4335 -

29 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-29 21:15

Updated : 2025-05-02 13:53


NVD link : CVE-2025-3501

Mitre link : CVE-2025-3501

CVE.ORG link : CVE-2025-3501


JSON object : View

Products Affected

No product.

CWE
CWE-297

Improper Validation of Certificate with Host Mismatch