A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 27 Nov 2024 21:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Redhat red Hat Single Sign On | |
| CPEs | cpe:/a:redhat:red_hat_single_sign_on:7 | |
| Vendors & Products | Redhat red Hat Single Sign On | 
Mon, 25 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Mon, 25 Nov 2024 07:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Title | keycloak-quarkus-server: Keycloak path trasversal | Keycloak-quarkus-server: keycloak path trasversal | 
| First Time appeared | Redhat jboss Enterprise Application Platform Redhat jbosseapxp | |
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:8 cpe:/a:redhat:jbosseapxp | |
| Vendors & Products | Redhat jboss Enterprise Application Platform Redhat jbosseapxp | |
| References |  | 
 | 
Fri, 22 Nov 2024 14:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not. | |
| Title | keycloak-quarkus-server: Keycloak path trasversal | |
| First Time appeared | Redhat Redhat build Keycloak | |
| Weaknesses | CWE-73 | |
| CPEs | cpe:/a:redhat:build_keycloak:24 cpe:/a:redhat:build_keycloak:24::el9 cpe:/a:redhat:build_keycloak:26 cpe:/a:redhat:build_keycloak:26.0::el9 | |
| Vendors & Products | Redhat Redhat build Keycloak | |
| References |  | |
| Metrics | threat_severity 
 | cvssV3_0 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2024-11-25T07:37:30.572Z
Updated: 2025-09-02T16:24:14.491Z
Reserved: 2024-10-29T13:07:47.731Z
Link: CVE-2024-10492
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-25T17:03:34.598Z
 NVD
                        NVD
                    Status : Received
Published: 2024-11-25T08:15:08.453
Modified: 2024-11-25T08:15:08.453
Link: CVE-2024-10492
 Redhat
                        Redhat