CVE-2025-0604
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 22, 2025
CWE ID 287
Summary
CVE-2025-0604 is a vulnerability affecting Keycloak, an identity and access management solution. The issue lies in the way Keycloak handles password resets for Active Directory (AD) users. Instead of validating new credentials against AD through an LDAP bind, the system directly updates the password. As a result, users with expired or disabled AD accounts can regain access to Keycloak, effectively bypassing AD restrictions. This vulnerability exposes the system to authentication bypass and unauthorized access risks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.