DirectorySecurity Advisories
Sign In
Security Advisories

CGA-qwx9-pqc4-38xv

Published

Last updated

https://images.chainguard.dev/security/CGA-qwx9-pqc4-38xv
Package

keycloak-operator

Latest Update
Fixed
Fixed Version

26.0.6-r0

Aliases
  • CVE-2024-10039
  • GHSA-93ww-43rr-79v3

Severity

7.1

High

CVSS V3

Summary

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

Description

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images