CVE-2023-1664 is a flaw in Keycloak, affecting Red Hat Keycloak, JBoss A-MQ, and other related products, that allows an attacker to bypass client certificate validation under specific non-default configurations. The vulnerability has a CVSS score of 6.5 (Medium) due to its network attack vector and low attack complexity, potentially impacting the confidentiality and integrity of consumer applications if the reverse proxy doesn't validate certificates and the Keycloak truststore is misconfigured. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:build_of_quarkus:-:*:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:redhat:jboss_a-mq:7:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:keycloak:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:redhat:migration_toolkit_for_runtimes:-:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.