Impact
The flaw lies in the SMTP configuration handling of the Keycloak services component. When STARTTLS is enabled, Keycloak does not strictly enforce an encrypted connection and can fall back to cleartext if the encryption request is tampered with. This behavior, identified as CWE‑319, permits attackers who intercept network traffic to capture email credentials and message content in plain text, resulting in a loss of confidentiality.
Affected Systems
Red Hat Build of Keycloak and Red Hat Single Sign‑On 7 are affected. The keycloak‑services component within these products processes SMTP settings, and the vulnerability exists in all current builds of these identifiers. Specific version ranges are not provided in the advisory, so any running instance that utilizes the default keycloak‑services SMTP configuration with STARTTLS enabled should be considered at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. EPSS data is unavailable, and the issue is not listed in the CISA KEV catalog. The likely attack vector is a network‑level attacker capable of modifying or observing SMTP commands. Without an official patch or workaround, the risk remains moderate; best‑practice controls can reduce exposure but will not eliminate the underlying design flaw.
OpenCVE Enrichment