-
Notifications
You must be signed in to change notification settings - Fork 8.2k
Closed
Labels
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.0.6release/26.1.0
Description
Description
A vulnerability was found in Keycloak. Deployments of Keycloak with a reverse proxy not using pass-through termination of TLS, with mTLS enabled, are affected. This issue may allow an attacker on the local network to authenticate as any user or client that leverages mTLS as the authentication mechanism.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
kind/bugCategorizes a PR related to a bugCategorizes a PR related to a bugkind/cveIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedIssues identified as CVEs on third-party dependencies, or issues which Keycloak is not affectedrelease/26.0.6release/26.1.0