CVE-2023-2422
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/errata/RHSA-2023:3883, https://access.redhat.com/errata/RHSA-2023:3884, https://access.redhat.com/errata/RHSA-2023:3885, https://access.redhat.com/errata/RHSA-2023:3888, https://access.redhat.com/errata/RHSA-2023:3892, https://access.redhat.com/security/cve/CVE-2023-2422, https://bugzilla.redhat.com/showbug.cgi?id=2191668, https://bugzilla.redhat.com/showbug.cgi?id=2191668
