Other nomination
mTLS: When certificate authentication is done wrong
Implementation flaws in mutual-TLS client authentication: servers that scan the whole certificate chain instead of only the first entry let an attacker impersonate another user with a self-signed certificate (Keycloak); certificate stores build LDAP filters from the unverified Subject field (Bouncy Castle); and revocation URLs read from certificate extensions give SSRF and leak the server's LDAP credentials (Apereo CAS).
Record
- Researcher
- Michael Stepankin
- Published by
- The GitHub Blog
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Michael Stepankin, first published at the original source. Preserved copies are kept so the citation survives its host.