CVE-2025-3501
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Vendor
-
Product
-
CWE
Yayın Tarihi
2025-04-29 21:15:51
Güncelleme
2025-08-07 13:15:36
Source Identifier
secalert@redhat.com
KEV Date Added
-
Kategoriler
Referanslar
https://access.redhat.com/errata/RHSA-2025:4335
https://access.redhat.com/errata/RHSA-2025:4336
https://access.redhat.com/errata/RHSA-2025:8672
https://access.redhat.com/errata/RHSA-2025:8690
https://access.redhat.com/security/cve/CVE-2025-3501
https://bugzilla.redhat.com/show_bug.cgi?id=2358834
https://github.com/keycloak/keycloak/issues/39350
https://github.com/keycloak/keycloak/pull/39366