RHSA-2025:2545MediumCVSS 7.5
Red Hat Security Advisory: Red Hat build of Keycloak 26.0.10 Update
🔗 CVE IDs covered (3)
📋 Description
CVE-2024-47072 — com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream CVE-2025-0604 — keycloak-ldap-federation: Authentication Bypass Due to Missing LDAP Bind After Password Reset in Keycloak CVE-2025-1391 — keycloak-services: Improper Authorization in Keycloak Organization Mapper Allows Unauthorized Organization Claims
🔗 References (5)
- selfhttps://access.redhat.com/errata/RHSA-2025:2545
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2338993
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2346082
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_2545.json