Launch Week Day 1: Announcing Security Design Review
HIGH 7.1 Maven

Keycloak mTLS Authentication Bypass via Reverse Proxy TLS Termination

GHSA-93ww-43rr-79v3 · CVE-2024-10039

Published · Modified

Description

A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.

Ready to move

Start Securing

Free, no credit card | First findings in minutes