{"id":"CVE-2020-35509","aliases":["GHSA-rpj2-w6fr-79hc"],"url":"https://o3.security/vulnerability/CVE-2020-35509","summary":"Keycloak vulnerable to Improper Certificate Validation","details":"keycloak accepts an expired certificate by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.\n\nThis issue was partially fixed in version [13.0.1](https://github.com/keycloak/keycloak/pull/6330) and more completely fixed in version [14.0.0](https://github.com/keycloak/keycloak/pull/8067).","published":"2022-08-23T16:15:08.950Z","modified":"2026-08-07T15:14:27.964736Z","cvss":{"score":5.4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.keycloak:keycloak-core","fixedVersion":"14.0.0"}],"fix":{"url":"https://github.com/keycloak/keycloak/pull/6330","label":"keycloak/keycloak#6330"},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2020-35509"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-35509"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/pull/6330"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/pull/8067"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/commit/478319348bdfdb9b6d39122f41edf2af79f679bb"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1912427"},{"type":"PACKAGE","url":"https://github.com/keycloak/keycloak"},{"type":"WEB","url":"https://github.com/keycloak/keycloak/blob/4f330f4a57cbfcf6202b60546518261c66e59a35/services/src/main/java/org/keycloak/authentication/authenticators/x509/ValidateX509CertificateUsername.java#L74-L76"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:14:27.964736Z"}}