Total vulnerabilities in the database
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
Software | From | Fixed in |
---|---|---|
![]() |
- | 21.1.2 |
redhat / openshift_container_platform | 4.9 | 4.9.x |
redhat / openshift_container_platform | 4.10 | 4.10.x |
redhat / openshift_container_platform | 4.11 | 4.11.x |
redhat / openshift_container_platform | 4.12 | 4.12.x |
redhat / single_sign-on | 7.6 | 7.6.x |