A flaw was found in Keycloak. A... CVE-2023-2422

- AV AC AU C I A
发布: 2023-10-04
修订: 2023-11-07

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.

0%
暂无可用Exp或PoC
当前有9条受影响产品信息