REDHAT-BUG-2338993: Medium severity Red Hat Keycloak vulnerability
The issue arises because Keycloak does not perform an LDAP bind after a password reset, leading to potential authentication bypass for expired or disabled AD accounts. A fix should enforce LDAP validation after password updates to ensure consistency with AD authentication policies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2338993?
The severity of REDHAT-BUG-2338993 is considered high due to the potential for authentication bypass.
How do I fix REDHAT-BUG-2338993?
Fixing REDHAT-BUG-2338993 involves updating Keycloak to enforce LDAP validation after password resets.
What versions of Keycloak are affected by REDHAT-BUG-2338993?
Red Hat Build of Keycloak is affected by REDHAT-BUG-2338993, though specific version listings are not provided.
What is the impact of REDHAT-BUG-2338993 on Active Directory accounts?
REDHAT-BUG-2338993 may lead to unauthorized access as it allows expired or disabled Active Directory accounts to authenticate.
Is there a known workaround for REDHAT-BUG-2338993?
There are no official workarounds for REDHAT-BUG-2338993; updating Keycloak is recommended to mitigate the issue.