You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Keycloak hostname verification
High severity
GitHub Reviewed
Published
Apr 30, 2025
in
keycloak/keycloak
•
Updated Aug 7, 2025
The product communicates with a host that provides a certificate, but the product does not properly ensure that the certificate is actually associated with that host.
Learn more on MITRE.
A flaw was found in Keycloak. By setting a verification policy to 'ANY', the trust store certificate verification is skipped, which is unintended.
References