CVE-2024-10492 LOW

CVE-2024-10492: Keycloak-quarkus-server: keycloak path trasversal

Vendor Red Hat
Product Red Hat build of Keycloak 24.0.9
Weakness CWE-73
Published November 25, 2024
Last update May 6, 2026

CVSS base score

2.7/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.

Key dates

02Disclosure timeline

November 25, 2024 CVE published
May 6, 2026 Record updated