/
DirectorySecurity Advisories
Sign In
Security Advisories

CVE-2024-10039

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-10039

CGA ID

CGA-5jh2-c8j7-f8m2

Severity

Unknown

Summary

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

Description

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

References

  • https://images.chainguard.dev/security/CGA-5jh2-c8j7-f8m2

Affected packages


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Products

Chainguard ContainersChainguard LibrariesChainguard VMs