CVE-2023-2422: Red Hat Keycloak

High severity, CVSS 7.1. EPSS: 0.5% chance of exploitation in the next 30 days.

A flaw was found in Keycloak. A Keycloak server configured to support mTLS authentication for OAuth/OpenID clients does not properly verify the client certificate chain. A client that possesses a proper certificate can authorize itself as any other client, therefore, access data that belongs to other clients.

Affected products

  • Red Hat Keycloak: affected versions not specified
  • Red Hat Openshift Container Platform: version 4.9 only; version 4.10 only; version 4.11 only; version 4.12 only
  • Red Hat Single Sign-On: version 7.6 only

Published 2023-10-04. Last modified 2026-06-17.