<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 03:13:53 +0000</lastBuildDate>
    <item>
      <title>bdu:2023-05659</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2023-05659</link>
      <description>bdu:2023-05659</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2023-05659</guid>
    </item>
    <item>
      <title>EUVD-2026-210678</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-210678</link>
      <description>EUVD-2026-210678</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-210678</guid>
    </item>
    <item>
      <title>fkie_cve-2023-1664</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-1664</link>
      <description>&lt;p&gt;A flaw was found in Keycloak. This flaw depends on a non-default configuration &amp;#34;Revalidate Client Certificate&amp;#34; to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variable is missing/misconfigured, any trustfile may be accepted with the logging information of &amp;#34;Cannot validate client certificate trust: Truststore not available&amp;#34;. This may not impact availability as the attacker would have no access to the server, but consumer applications Integrity or Confidentiality may be impacted considering a possible access to them. Considering the environment is correctly set to use &amp;#34;Revalidate Client Certificate&amp;#34; this flaw is avoidable.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A flaw was found in Keycloak. This flaw depends on a non-default configuration &amp;#34;Revalidate Client Certificate&amp;#34; to be enabled and the reverse proxy is not validating the certificate before Keycloak. Using this method an attacker may choose the certificate which will be validated by the server. If this happens and the KC_SPI_TRUSTSTORE_FILE_FILE variable is missing/misconfigured, any trustfile may be accepted with the logging information of &amp;#34;Cannot validate client certificate trust: Truststore not available&amp;#34;. This may not impact availability as the attacker would have no access to the server, but consumer applications Integrity or Confidentiality may be impacted considering a possible access to them. Considering the environment is correctly set to use &amp;#34;Revalidate Client Certificate&amp;#34; this flaw is avoidable.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-1664</guid>
    </item>
    <item>
      <title>GHSA-5cc8-pgp5-7mpm — Keycloak Untrusted Certificate Validation vulnerability</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5cc8-pgp5-7mpm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A flaw was found in keycloak-core. This flaw considers the scenario when using X509 Client Certificate Authenticatior with the option &amp;#34;Revalidate Client Certificate&amp;#34;. A user may be able to choose, if directly connect to keycloak (not passing via reverse proxy) a specific certificate. If there&amp;#39;s a configuration error in KC_SPI_TRUSTSTORE_FILE_FILE the authenticator allows even with the &amp;#34;Cannot validate client certificate trust: Truststore not available&amp;#34; message as there&amp;#39;s no certificate to trust against.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.keycloak:keycloak-core&lt;/p&gt;
&lt;p&gt;A flaw was found in keycloak-core. This flaw considers the scenario when using X509 Client Certificate Authenticatior with the option &amp;#34;Revalidate Client Certificate&amp;#34;. A user may be able to choose, if directly connect to keycloak (not passing via reverse proxy) a specific certificate. If there&amp;#39;s a configuration error in KC_SPI_TRUSTSTORE_FILE_FILE the authenticator allows even with the &amp;#34;Cannot validate client certificate trust: Truststore not available&amp;#34; message as there&amp;#39;s no certificate to trust against.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5cc8-pgp5-7mpm</guid>
    </item>
    <item>
      <title>gsd-2023-1664</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-1664</link>
      <description>gsd-2023-1664</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-1664</guid>
    </item>
    <item>
      <title>RHSA-2023:3883 — Red Hat Security Advisory: Red Hat Single Sign-On 7.6.4 security update on RHEL 7</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2023:3883</link>
      <description>&lt;p&gt;RHSSO: XSS due to lax URI scheme validation Undertow: Infinite loop in SslConduit during close keycloak: Untrusted Certificate Validation keycloak: oauth client impersonation keycloak: client access via device auth request spoof&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;RHSSO: XSS due to lax URI scheme validation Undertow: Infinite loop in SslConduit during close keycloak: Untrusted Certificate Validation keycloak: oauth client impersonation keycloak: client access via device auth request spoof&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2023:3883</guid>
    </item>
    <item>
      <title>WID-SEC-W-2023-0764 — Keycloak: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0764</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Keycloak und Red Hat Single Sign On ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Keycloak und Red Hat Single Sign On ausnutzen, um Sicherheitsvorkehrungen zu umgehen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2023-0764</guid>
    </item>
  </channel>
</rss>
