CVE-2024-10039

HIGH7.1

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

發布日:2024/11/25修改日:2026/2/4
也稱為:GHSA-93ww-43rr-79v3CGA-5m29-pjcj-vjv6

描述

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

參考連結(3)