CVE-2024-11736
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Jan 14, 2025
CWE ID 526
Summary
CVE-2024-11736 is a newly identified vulnerability affecting Keycloak. It allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. By including placeholders like ${env.VARNAME} or ${PROPNAME} in backchannel logout URLs or admin URLs, attackers can potentially gain unauthorized access to critical information during URL processing. This vulnerability poses a significant risk and emphasizes the importance of securely managing server configurations.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.