VDB
Sign up
HIGH7.1

GHSA-93ww-43rr-79v3

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

Quick fix

GHSA-93ww-43rr-79v3 — org.keycloak:keycloak-core: upgrade to the fixed version with the command below.

# pom.xml: bump <version>26.0.6</version> for org.keycloak:keycloak-core

Details

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.keycloak:keycloak-core
Introduced in: 0Fixed in: 26.0.6
Fix# pom.xml: bump <version>26.0.6</version> for org.keycloak:keycloak-core

References