Impact
A flaw was discovered in Keycloak’s Kerberos federation provider, where the system does not validate the Key Distribution Center (KDC) during Kerberos password authentication when SPNEGO is not used. This omission allows an attacker on the same network to act as a fake KDC, thereby bypassing the authentication process and gaining unauthorized access to user accounts. The weakness is identified as CWE‑347, indicating potential spoofing of network traffic. The impact is the escape of authentication controls, leading to compromised accounts without requiring additional privileges.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign‑On 7. Specific version information is not provided in the available data, so the recommendation applies to all current deployments until a product‑level fix is issued.
Risk and Exploitability
The CVSS score of 6.8 classifies this as a medium‑severity vulnerability. EPSS information is not available, so the likelihood of exploitation cannot be quantified, but the lack of KDC validation makes local network bypass feasible. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation instances have been reported. Based on the description, attackers would need local network proximity to reach the KDC service, and the path involves impersonating the KDC to obtain service tickets. In the absence of additional requirements, the vulnerability can be considered an authentication bypass that riskfully compromises confidentiality of user accounts.
OpenCVE Enrichment