A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2023-10-04T10:59:30.818Z
Updated: 2024-08-02T06:19:15.138Z
Reserved: 2023-04-28T17:33:42.062Z
Link: CVE-2023-2422
Vulnrichment
Updated: 2024-08-02T06:19:15.138Z
NVD
Status : Modified
Published: 2023-10-04T11:15:10.157
Modified: 2023-11-07T04:12:40.367
Link: CVE-2023-2422
Redhat