DirectorySecurity Advisories
Sign In
Security Advisories

CGA-339h-m87p-4mff

Published

Last updated

https://images.chainguard.dev/security/CGA-339h-m87p-4mff
Package

keycloak-fips

Latest Update
Fixed
Fixed Version

26.0.6-r0

Aliases
  • CVE-2024-10039
  • GHSA-93ww-43rr-79v3

Severity

7.1

High

CVSS V3

Summary

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

Description

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images