Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.4 Maven

Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak

GHSA-2p82-5wwr-43cw · CVE-2025-0604

Published · Modified

Description

The issue arises because Keycloak does not perform an LDAP bind after a password reset, leading to potential authentication bypass for expired or disabled AD accounts. A fix should enforce LDAP validation after password updates to ensure consistency with AD authentication policies.

Ready to move

Start Securing

Free, no credit card | First findings in minutes