PT-2024-9024 · Red Hat+1 · Keycloak+1
CVSS v4.0
8.2
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Keycloak versions prior to 26.0.2
Description
Sensitive runtime values, such as passwords, may be captured during the build process and embedded as default values in bytecode, leading to unintended information disclosure. In version 26, sensitive data specified directly in environment variables during the build process is also stored as default values, making it accessible during runtime. Additionally, the indirect use of environment variables for SPI options and Quarkus properties is vulnerable due to unconditional expansion by the
PropertyMapper logic, which captures sensitive data as default values.Recommendations
Update Keycloak to version 26.0.2 or later.
Fix
Information Disclosure
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Keycloak