{"id":"CVE-2020-35509","details":"A flaw was found in keycloak affecting versions 11.0.3 and 12.0.0. An expired certificate would be accepted by the direct-grant authenticator because of missing time stamp validations. The highest threat from this vulnerability is to data confidentiality and integrity.","aliases":["GHSA-rpj2-w6fr-79hc"],"modified":"2026-08-07T15:14:27.964736Z","published":"2022-08-23T16:15:08.950Z","references":[{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/cve-2020-35509"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keycloak/keycloak","events":[{"introduced":"da186af13d137f6ba7604b685cc8d0df3382494d"},{"last_affected":"2690229863ddbcdfa2c75e00a7a9858e2e03c6c9"}],"database_specific":{"cpe":["cpe:2.3:a:redhat:keycloak:11.0.3:*:*:*:*:*:*:*","cpe:2.3:a:redhat:keycloak:12.0.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"11.0.3"},{"last_affected":"11.0.3"},{"introduced":"12.0.0"},{"last_affected":"12.0.0"}],"source":"CPE_STRING"}}],"versions":["11.0.3","12.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-35509.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N"}]}