Impact
An attacker can supply a crafted client certificate that causes the Keycloak X.509 authenticator to read arbitrary files from the server filesystem or load extremely large files, leading to disclosure of sensitive data or a memory exhaustion induced crash. The flaw lies in the CRL Distribution Point path validation, which is not properly sanitized. The weakness is a local path traversal error that can be exploited when CRL checking is enabled.
Affected Systems
The vulnerability affects Red Hat Build of Keycloak and Red Hat Single Sign-On 7. No specific affected versions are listed, so any installation that includes the X.509 client certificate authenticator with CRL checking enabled is potentially impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. The EPSS score is not available, so the current exploitation probability has not been quantified. The vulnerability is not listed in CISA KEV, suggesting there are no known active exploits at this time. The likely attack vector requires the attacker to be able to influence the client certificate presented to the server, which typically means they have some foothold in the authentication process or can inject certificates into the system.
OpenCVE Enrichment