A flaw was found in Keycloak. By setting a verification policy to 'ALL', the trust store certificate verification is skipped, which is unintended.
rhbk/keycloak Red Hat / RHEL
Fixed in: rhel9@sha256:76f2963c284d0a79e6026bee0837639bce5af84a18c994828aa0890923725189_s390x RHSA-2025:4335 Fixed in: rhel9-operator@sha256:acd2a3adf7365e62689b79608c2289c804f47f97a81f9e8ddf3fecdce6d6f0ec_s390x RHSA-2025:4335 Fixed in: rhel9@sha256:67699f3ec6e1a489b769523d9deaeec57a8113259d375501aa043778828c2286_amd64 RHSA-2025:4335 Fixed in: operator-bundle@sha256:67a4498b9c68a7068cc2bcfa2d7d5eb35e6ec7e281c0886893f4125a6487c8a1_amd64 RHSA-2025:4335 Fixed in: rhel9-operator@sha256:83c90cf0627a1b99900d539f417e648d8be4c9966452872a93a8236e17b1d1cf_amd64 RHSA-2025:4335 Fixed in: rhel9@sha256:87ff67880fd7f44174b263759c99f4d701cf208eeb6f4abf636a10b98ec023d0_ppc64le RHSA-2025:4335 Fixed in: rhel9-operator@sha256:8e1a37dc9fa7b99a65ac9997d49bc9991172a461c63196614d1975bc2210e7fa_ppc64le RHSA-2025:4335 Fixed in: rhel9@sha256:e24acc11a1bc60321cec78a5f2bc2521636fe00fddd9e742d7b25131f3152c5a_ppc64le RHSA-2025:8672 Fixed in: rhel9-operator@sha256:2a85cb76b1d5cd7cf2a8b0d809249470b049ae5b8de32186ceac4ae13e7758e3_ppc64le RHSA-2025:8672 Fixed in: rhel9@sha256:55062a4e89ec53f2759aeb7fe5f117a658e182ee898a78074f47330943ff14eb_s390x RHSA-2025:8672 Fixed in: rhel9-operator@sha256:2cb97ec2a8ac79b31a678d348b2217e008d39b1f8482e75c1baf8acc026910c1_s390x RHSA-2025:8672 Fixed in: rhel9@sha256:e3e211f233016ade5c98aa16f979d97a90c8af369bc81cd526e2a40e53ed4daa_amd64 RHSA-2025:8672 Fixed in: operator-bundle@sha256:4ecfe1e2059cc2d7087e01ae04598bd5628f2958c21e14e41fa249dccf0d3e5f_amd64 RHSA-2025:8672 Fixed in: rhel9-operator@sha256:35d37a09fa0a9799258aede346e1cb205179617ab2e417c809e18dee2ed1860a_amd64 RHSA-2025:8672 Fixed in: rhel9@sha256:b87e36a465c9a84edc7b74ac46ca555cd5189731eaeec9da7f05f1e41cc86e70_arm64 RHSA-2025:8672 Fixed in: rhel9-operator@sha256:c9d86fff34b796441318e5fd211b69f07b4aaacfd49f7d2b02d972329cb61d83_arm64 RHSA-2025:8672 rhbk/keycloak Rocky
Fixed in: rhel9@sha256:76f2963c284d0a79e6026bee0837639bce5af84a18c994828aa0890923725189_s390x RHSA-2025:4335 Fixed in: rhel9-operator@sha256:acd2a3adf7365e62689b79608c2289c804f47f97a81f9e8ddf3fecdce6d6f0ec_s390x RHSA-2025:4335 Fixed in: rhel9@sha256:67699f3ec6e1a489b769523d9deaeec57a8113259d375501aa043778828c2286_amd64 RHSA-2025:4335 Fixed in: operator-bundle@sha256:67a4498b9c68a7068cc2bcfa2d7d5eb35e6ec7e281c0886893f4125a6487c8a1_amd64 RHSA-2025:4335 Fixed in: rhel9-operator@sha256:83c90cf0627a1b99900d539f417e648d8be4c9966452872a93a8236e17b1d1cf_amd64 RHSA-2025:4335 Fixed in: rhel9@sha256:87ff67880fd7f44174b263759c99f4d701cf208eeb6f4abf636a10b98ec023d0_ppc64le RHSA-2025:4335 Fixed in: rhel9-operator@sha256:8e1a37dc9fa7b99a65ac9997d49bc9991172a461c63196614d1975bc2210e7fa_ppc64le RHSA-2025:4335 Fixed in: rhel9@sha256:e24acc11a1bc60321cec78a5f2bc2521636fe00fddd9e742d7b25131f3152c5a_ppc64le RHSA-2025:8672 Fixed in: rhel9-operator@sha256:2a85cb76b1d5cd7cf2a8b0d809249470b049ae5b8de32186ceac4ae13e7758e3_ppc64le RHSA-2025:8672 Fixed in: rhel9@sha256:55062a4e89ec53f2759aeb7fe5f117a658e182ee898a78074f47330943ff14eb_s390x RHSA-2025:8672 Fixed in: rhel9-operator@sha256:2cb97ec2a8ac79b31a678d348b2217e008d39b1f8482e75c1baf8acc026910c1_s390x RHSA-2025:8672 Fixed in: rhel9@sha256:e3e211f233016ade5c98aa16f979d97a90c8af369bc81cd526e2a40e53ed4daa_amd64 RHSA-2025:8672 Fixed in: operator-bundle@sha256:4ecfe1e2059cc2d7087e01ae04598bd5628f2958c21e14e41fa249dccf0d3e5f_amd64 RHSA-2025:8672 Fixed in: rhel9-operator@sha256:35d37a09fa0a9799258aede346e1cb205179617ab2e417c809e18dee2ed1860a_amd64 RHSA-2025:8672 Fixed in: rhel9@sha256:b87e36a465c9a84edc7b74ac46ca555cd5189731eaeec9da7f05f1e41cc86e70_arm64 RHSA-2025:8672 Fixed in: rhel9-operator@sha256:c9d86fff34b796441318e5fd211b69f07b4aaacfd49f7d2b02d972329cb61d83_arm64 RHSA-2025:8672 TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
Exploitability
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Impact
Confidentiality High
Integrity Low
Availability None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
0.41% probability of exploitation in 30 days
33rd percentile
Low risk: more likely to be exploited than 33% of all known CVEs.
Other CWE-297 vulnerabilities, ordered by exploit likelihood. View all
Embed a live status badge for CVE-2025-3501 Markdown
[](https://tridentstack.com/cve/CVE-2025-3501)HTML
<a href="https://tridentstack.com/cve/CVE-2025-3501"><img src="https://tridentstack.com/cve/badge/CVE-2025-3501.svg" alt="CVE-2025-3501"></a>Find and fix vulnerabilities across your fleet TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-08-07.