First published: Wed Apr 30 2025(Updated: )
A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.keycloak:keycloak-services | <26.2.2 | 26.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of GHSA-hw58-3793-42gg is classified as critical due to the potential risk of certificate verification being bypassed.
To fix GHSA-hw58-3793-42gg, update your Keycloak installation to version 26.2.2 or later.
The consequences of GHSA-hw58-3793-42gg include the risk of accepting untrusted certificates, which could lead to man-in-the-middle attacks.
GHSA-hw58-3793-42gg affects all Keycloak versions prior to 26.2.2.
The flaw in GHSA-hw58-3793-42gg allows the trust store certificate verification to be skipped when a verification policy is set to 'ALL'.