PT-2025-1684 · Red Hat+1 · Keycloak+1

Steven Hawkins

·

Published

2025-01-13

·

Updated

2025-11-01

·

CVE-2024-11736

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Keycloak (affected versions not specified)
Description A security issue allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
CVE-2024-11736
GHSA-F4V7-3MWW-9GC2

Affected Products

Alt Linux
Keycloak