Improper Authentication in Keycloak - CVE-2024-10039
Published: November 25, 2024
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in the authentication process in the Keycloak deployments with a reverse proxy not using pass-through termination of TLS and with enabled mTLS. A remote attacker can authenticate as any user or client that leverages mTLS as the authentication mechanism.
Affected software
Red Hat build of Keycloak
How to mitigate CVE-2024-10039
Red Hat build of Keycloak - addressed in versions 24.0.9, 26.0.6