CVE-2024-10973
CVSS 3.1 Score 5.7 of 10 (medium)
Details
Published Dec 17, 2024
CWE ID 319
Summary
CVE-2024-10973 is a newly discovered vulnerability affecting Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED`, intended to enable encrypted communication, is not functioning properly. Instead, the JGroups replication configuration is always used in plain text. This misconfiguration exposes sensitive information to potential attackers who gain access to adjacent networks related to JGroups, making it essential for Keycloak users to apply the necessary patches to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share