CVE-2025-3501
CVSS 3.1 Score 8.2 of 10 (high)
Details
Published Apr 29, 2025
Updated: May 2, 2025
CWE ID 297
Summary
CVE-2025-3501 is a vulnerability affecting Keycloak, an identity and access management solution. When the verification policy is set to 'ALL', the system mistakenly bypasses certificate verification in the trust store, which is not intended and poses a security risk. An attacker could exploit this issue to gain unauthorized access to protected systems or data. It is recommended that users update their Keycloak installations to the latest version to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.