GHSA-rpj2-w6fr-79hc
GitHub Security Advisory
Keycloak vulnerable to Improper Certificate Validation
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.
This issue was partially fixed in version [13.0.1](https://github.com/keycloak/keycloak/pull/6330) and more completely fixed in version [14.0.0](https://github.com/keycloak/keycloak/pull/8067).
Affected Packages
Maven
org.keycloak:keycloak-core
Affected versions:
0
(fixed in 14.0.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.