We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
A flaw was found in Keycloak. The org.keycloak.authorization package may be vulnerable to circumventing required actions, allowing users to circumvent requirements such as setting up two-factor authentication.
Reserved 2025-04-23 | Published 2025-04-29 | Updated 2025-04-30 | Assigner redhat2025-04-23: | Reported to Red Hat. |
2025-04-29: | Made public. |
This issue was discovered by Marek Posolda (Red Hat).
access.redhat.com/errata/RHSA-2025:4335 (RHSA-2025:4335)
access.redhat.com/errata/RHSA-2025:4336 (RHSA-2025:4336)
access.redhat.com/security/cve/CVE-2025-3910
bugzilla.redhat.com/show_bug.cgi?id=2361923 (RHBZ#2361923)
Support options