Описание
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
Отчет
The Red Hat Product Security team has assessed the severity of this vulnerability as Moderate, given that it requires non-default configurations (crl-checking-enabled and crldp-checking-enabled) to be active. Successful exploitation allows an attacker to perform arbitrary local file read attempts, potentially leaking file existence or metadata, and cause a Denial of Service through memory exhaustion. The vulnerabilitys root cause is a lack of path normalization and containment checks on the CRL Distribution Point value provided in X.509 certificates.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Keycloak | keycloak-services | Affected | ||
| Red Hat Build of Keycloak | rhbk/keycloak-rhel9 | Affected | ||
| Red Hat Single Sign-On 7 | keycloak-services | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
A flaw was found in the X.509 client certificate authenticator of Keyc ...
A flaw was found in the X.509 client certificate authenticator of Keycloak. When CRL Distribution Point checking is enabled, the server fails to properly validate the file paths provided in a client certificate. An attacker can provide a specially crafted certificate that causes the server to attempt to read sensitive files from the local system or exhaust memory by loading extremely large files, potentially leading to information disclosure or a system crash.
EPSS
6.5 Medium
CVSS3