PT-2024-9010 · Red Hat · Keycloak

CVE-2024-10039

·

Published

2024-10-16

·

Updated

2024-11-26

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Keycloak (affected versions not specified)
Description: The issue is related to an error in certificate authentication in the implementation of the mTLS protocol in Keycloak, which is a software tool for identity and access management. This could allow an attacker to bypass security restrictions and gain unauthorized access to protected information. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, and with mTLS enabled, are affected. An attacker on the local network may authenticate as any user or client that uses mTLS as the authentication mechanism.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Certificate Validation

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10692
CVE-2024-10039
GHSA-93WW-43RR-79V3

Affected Products

Keycloak