Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw was found in the keycloak-services component where it fails to properly validate the KDC identity during Kerberos password authentication. When Kerberos password mode is enabled without SPNEGO/negotiate authentication, Keycloak does not request a server ticket in the name of the authenticating user to verify the KDC response. An attacker capable of performing DNS, ARP, or DHCP spoofing on the local network can provide a fraudulent KDC response. Successful exploitation allows an attacker to bypass authentication entirely and impersonate any user, leading to unauthorized access to sensitive data and administrative functions.