PT-2026-97836 · Red Hat+1 · Keycloak+1
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Liman Render Engine versions 1.0 through 1.2-74
Description
Improper certificate validation in the Liman Render Engine allows an Adversary in the Middle (AiTM) attack. This occurs because TLS certificate validation is disabled for Keycloak connections.
Recommendations
Update Liman Render Engine to version 1.2-75 or later.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Keycloak
Liman Render Engine