PT-2024-9024 · Red Hat+1 · Keycloak+1

·

CVE-2024-10451

·

Published

2024-10-28

·

Updated

2026-08-31

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Keycloak versions prior to 26.0.2
Description Sensitive runtime values, such as passwords, may be captured during the build process and embedded as default values in bytecode, leading to unintended information disclosure. In version 26, sensitive data specified directly in environment variables during the build process is also stored as default values, making it accessible during runtime. Additionally, the indirect use of environment variables for SPI options and Quarkus properties is vulnerable due to unconditional expansion by the PropertyMapper logic, which captures sensitive data as default values.
Recommendations Update Keycloak to version 26.0.2 or later.

Fix

Information Disclosure

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2025-13422
ALT-PU-2025-2871
BDU:2024-10706
CVE-2024-10451
ECHO-FEA2-5EA1-2849
GHSA-JCGG-MG9G-P9WF
GHSA-V7GV-XPGF-6395

Affected Products

Alt Linux
Keycloak