CVE-2023-2422
published 2023-10-04CVE-2023-2422: A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client…
PriorityP340high7.1CVSS 3.1
AVNACLPRLUINSUCHILAN
EPSS
0.52%
40.8th percentile
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | openshift_container_platform | — | — |
| redhat | single_sign-on | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
ghsa·2023-06-30
CVE-2023-2422 [HIGH] CWE-295 Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
When a Keycloak server is configured to support mTLS authentication for OAuth/OpenID clients, it does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client and therefore access data that belongs to other clients.
OSV
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
osv·2023-06-30
CVE-2023-2422 [HIGH] Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
Keycloak vulnerable to Improper Client Certificate Validation for OAuth/OpenID clients
When a Keycloak server is configured to support mTLS authentication for OAuth/OpenID clients, it does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client and therefore access data that belongs to other clients.
Red Hat
keycloak: oauth client impersonation
vendor_redhat·2023-06-26·CVSS 5.5
CVE-2023-2422 [MEDIUM] CWE-295 keycloak: oauth client impersonation
keycloak: oauth client impersonation
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://access.redhat.com/errata/RHSA-2023:3883https://access.redhat.com/errata/RHSA-2023:3884https://access.redhat.com/errata/RHSA-2023:3885https://access.redhat.com/errata/RHSA-2023:3888https://access.redhat.com/errata/RHSA-2023:3892https://access.redhat.com/security/cve/CVE-2023-2422https://bugzilla.redhat.com/show_bug.cgi?id=2191668https://access.redhat.com/errata/RHSA-2023:3883https://access.redhat.com/errata/RHSA-2023:3884https://access.redhat.com/errata/RHSA-2023:3885https://access.redhat.com/errata/RHSA-2023:3888https://access.redhat.com/errata/RHSA-2023:3892https://access.redhat.com/security/cve/CVE-2023-2422https://bugzilla.redhat.com/show_bug.cgi?id=2191668
2023-10-04
Published