HIGH 7.1 Maven
Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination
GHSA-93ww-43rr-79v3 · CVE-2024-10039
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.
Ready to move
Start Securing
Free, no credit card | First findings in minutes