HIGH7.1
GHSA-93ww-43rr-79v3
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
Quick fix
GHSA-93ww-43rr-79v3 — org.keycloak:keycloak-core: upgrade to the fixed version with the command below.
# pom.xml: bump <version>26.0.6</version> for org.keycloak:keycloak-coreDetails
A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.keycloak:keycloak-core
Introduced in:
0Fixed in: 26.0.6Fix
# pom.xml: bump <version>26.0.6</version> for org.keycloak:keycloak-core