Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process
Summary
| CVE | CVE-2024-10451 |
|---|---|
| State | PUBLISHED |
| Assigner | redhat |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2024-11-25 08:15:07 UTC |
| Updated | 2026-08-04 20:16:45 UTC |
| Description | A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data specified directly in environment variables during the build process is also stored as a default values, making it accessible during runtime. Indirect usage of environment variables for SPI options and Quarkus properties is also vulnerable due to unconditional expansion by PropertyMapper logic, capturing sensitive data as default values in all Keycloak versions up to 26.0.2. |
Risk And Classification
Primary CVSS: v3.1 5.9 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.009370000 probability, percentile 0.573890000 (date 2026-08-04)
Problem Types: CWE-798 | CWE-798 Use of Hard-coded Credentials
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 5.9 | MEDIUM | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Red Hat | Red Hat Build Of Keycloak 24 | unaffected 24.0.9-1 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 24 | unaffected 24-18 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 24 | unaffected 24-18 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 24.0.9 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.0 | unaffected 26.0.6-2 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.0 | unaffected 26.0-5 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.0 | unaffected 26.0-6 * rpm | Not specified |
| CNA | Red Hat | Red Hat Build Of Keycloak 26.0.6 | Not specified | Not specified |
| CNA | Red Hat | Red Hat JBoss Enterprise Application Platform 8 | Not specified | Not specified |
| CNA | Red Hat | Red Hat Single Sign-On 7 | Not specified | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/security/cve/CVE-2024-10451 | [email protected] | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | [email protected] | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2024:10178 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:10175 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:10176 | [email protected] | access.redhat.com | |
| access.redhat.com/errata/RHSA-2024:10177 | [email protected] | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Red Hat would like to thank Steven Hawkins for reporting this issue. (en)
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| CNA | 2024-10-28T07:27:41.800Z | Reported to Red Hat. |
| CNA | 2024-11-21T16:55:00.000Z | Made public. |
There are currently no legacy QID mappings associated with this CVE.