Red Hat · Keycloak · CVE-2024-10973
**Name of the Vulnerable Software and Affected Versions**
Keycloak (affected versions not specified)
**Description**
A vulnerability was found in Keycloak where the environment option `KC CACHE EMBEDDED MTLS ENABLED` does not work, and the JGroups replication configuration is always used in plain text. This can allow an attacker with access to adjacent networks related to JGroups to read sensitive information.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.