Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.keycloak/keycloak-quarkus-server
  4. ›
  5. GHSA-6mpx-pmgp-ww49

GHSA-6mpx-pmgp-ww49: Duplicate Advisory: Keycloak vulnerable to Cleartext Transmission of Sensitive Information

December 18, 2024 (updated February 5, 2025)

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-g6qq-c9f9-2772. This link is maintained to preserve external references.

Original Description

A vulnerability was found in Keycloak. The environment option KC_CACHE_EMBEDDED_MTLS_ENABLED does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.

References

  • access.redhat.com/security/cve/CVE-2024-10973
  • bugzilla.redhat.com/show_bug.cgi?id=2324361
  • github.com/advisories/GHSA-6mpx-pmgp-ww49
  • github.com/keycloak/keycloak
  • github.com/keycloak/keycloak/commit/071032a108bd9e9fce9e66d00c36d56bd4b334df
  • github.com/keycloak/keycloak/commit/36defd5f33b2da5d705f179bbaa21c28b13a9996
  • github.com/keycloak/keycloak/issues/28750
  • github.com/keycloak/keycloak/issues/34644
  • github.com/keycloak/keycloak/pull/28756
  • github.com/keycloak/keycloak/pull/34668
  • nvd.nist.gov/vuln/detail/CVE-2024-10973

Code Behaviors & Features

Detect and mitigate GHSA-6mpx-pmgp-ww49 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 25.0.0 before 26.0.6

Fixed versions

  • 26.0.6

Solution

Upgrade to version 26.0.6 or above.

Impact 5.7 MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-319: Cleartext Transmission of Sensitive Information

Source file

maven/org.keycloak/keycloak-quarkus-server/GHSA-6mpx-pmgp-ww49.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:42 +0000.