#VU102570 Information disclosure in Keycloak - CVE-2024-11736
Published: January 13, 2025
Keycloak
Keycloak
Description
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to the application discloses values of environment variables via user-configurable URLs. A remote user can configure backchannel logout URLs or admin URLs with placeholders like ${env.VARNAME} or ${PROPNAME} and gain access to sensitive information.