PT-2024-16676 · Red Hat · Keycloak

Philliphnguyen

·

Published

2024-12-17

·

Updated

2025-02-05

·

CVE-2024-10973

CVSS v3.1

5.7

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A vulnerability was found in Keycloak where the environment option KC CACHE EMBEDDED MTLS ENABLED does not work, and the JGroups replication configuration is always used in plain text. This can allow an attacker with access to adjacent networks related to JGroups to read sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-10973
GHSA-6MPX-PMGP-WW49
GHSA-G6QQ-C9F9-2772

Affected Products

Keycloak