CVE-2024-11736

CVSS 3.1 Score 4.9 of 10 (medium)

Details

Published Jan 14, 2025
CWE ID 526

Summary

CVE-2024-11736 is a newly identified vulnerability affecting Keycloak. It allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. By including placeholders like ${env.VARNAME} or ${PROPNAME} in backchannel logout URLs or admin URLs, attackers can potentially gain unauthorized access to critical information during URL processing. This vulnerability poses a significant risk and emphasizes the importance of securely managing server configurations.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share