keycloak: Untrusted Certificate Validation
Published May 26, 2023
6.5
MEDIUMCVSS 3.1
EPSS 0.43%
Description
A flaw was found in Keycloak. This flaw depends on a non-default configuration "Revalidate Client Certificate" to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variable is missing/misconfigured, any trustfile may be accepted with the logging information of "Cannot validate client certificate trust: Truststore not available". This may not impact availability as the attacker would have no access to the server, but consumer applications Integrity or Confidentiality may be impacted considering a possible access to them. Considering the environment is correctly set to use "Revalidate Client Certificate" this flaw is avoidable.
Affected products
- Vendor n/a Product Keycloak Defaultn/a
- Version NAStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Keycloak | n/a |
|
- n/a
- 7
- n/a
- n/a
- 7.0
No data.
AMQ Broker 7.11.2
keycloak-core
Fixed · RHSA-2023:5491
RHEL-8 based Middleware Containers
rh-sso-7/sso76-openshift-rhel8:7.6-24
Fixed · RHSA-2023:3888
Red Hat Single Sign-On 7
rh-sso7-keycloak
Fixed · RHSA-2023:3892
Red Hat Single Sign-On 7.6 for RHEL 7
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el7sso
Fixed · RHSA-2023:3883
Red Hat Single Sign-On 7.6 for RHEL 8
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso
Fixed · RHSA-2023:3884
Red Hat Single Sign-On 7.6 for RHEL 9
rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el9sso
Fixed · RHSA-2023:3885
Migration Toolkit for Runtimes
org.keycloak-keycloak-core
Affected
Red Hat Fuse 7
keycloak-core
Fix deferred
Red Hat Satellite 6
keycloak-httpd-client-install
Not affected
Red Hat build of Apicurio Registry 2
keycloak-core
Fix deferred
Red Hat build of Quarkus
keycloak-core
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Broker 7.11.2 | keycloak-core | Fixed | RHSA-2023:5491 |
| RHEL-8 based Middleware Containers | rh-sso-7/sso76-openshift-rhel8:7.6-24 | Fixed | RHSA-2023:3888 |
| Red Hat Single Sign-On 7 | rh-sso7-keycloak | Fixed | RHSA-2023:3892 |
| Red Hat Single Sign-On 7.6 for RHEL 7 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el7sso | Fixed | RHSA-2023:3883 |
| Red Hat Single Sign-On 7.6 for RHEL 8 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso | Fixed | RHSA-2023:3884 |
| Red Hat Single Sign-On 7.6 for RHEL 9 | rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el9sso | Fixed | RHSA-2023:3885 |
| Migration Toolkit for Runtimes | org.keycloak-keycloak-core | Affected | n/a |
| Red Hat Fuse 7 | keycloak-core | Fix deferred | n/a |
| Red Hat Satellite 6 | keycloak-httpd-client-install | Not affected | n/a |
| Red Hat build of Apicurio Registry 2 | keycloak-core | Fix deferred | n/a |
| Red Hat build of Quarkus | keycloak-core | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Red Hat Impact rated as a low impact considering there's a mitigation for this issue which would be consider the environment is correctly set with the truststore file. With these settings, the environment there's no evidence of attack possibility. Also it's possible to track under the server logs for more evidences.
Red Hat mitigation
Make sure KC_SPI_TRUSTSTORE_FILE_FILE is correctly set and the logs are not reporting the "Cannot validate client certificate trust: Truststore not available" after an attempt to explore the vulnerability. Note this message may happen under other scenarios and reasons but the expected behavior would be that a non-valid certificate to pass.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Jan 15, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2023–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (8 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.43% (0.00425) | 34.45th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00425) | 33.73th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.20% (0.00204) | 40.53th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00054) | 23.81th | v3 (v2023.03.01) |
| Jun 1, 2024 | 0.05% (0.00050) | 19.38th | v3 (v2023.03.01) |
| Apr 27, 2024 | 0.05% (0.00047) | 16.01th | v3 (v2023.03.01) |
| Jun 3, 2023 | 0.05% (0.00046) | 13.99th | v3 (v2023.03.01) |
| May 27, 2023 | 0.04% (0.00043) | 7.04th | v3 (v2023.03.01) |
References (7)
- https://access.redhat.com/security/cve/CVE-2023-1664 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2182196 Issue Tracking
- https://bugzilla.redhat.com/show_bug.cgi?id=2182196&comment#0 Issue TrackingVendor Advisory
- https://github.com/advisories/GHSA-5cc8-pgp5-7mpm Advisory
- https://github.com/keycloak/keycloak/security/advisories/GHSA-5cc8-pgp5-7mpm
- https://nvd.nist.gov/vuln/detail/CVE-2023-1664
- https://www.cve.org/CVERecord?id=CVE-2023-1664
Change history (0)
No recorded changes yet.