Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gv3v-2cpp-3pmq

Опубликовано: 10 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

Keycloak logs sensitive headers

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

Patches are available, see:

Пакеты

Наименование

org.keycloak:keycloak-quarkus-server

maven
Затронутые версииВерсия исправления

< 26.5.6

26.5.6

EPSS

Процентиль: 4%
0.00141
Низкий

5 Medium

CVSS3

Дефекты

CWE-117

Связанные уязвимости

CVSS3: 5
redhat
11 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
nvd
7 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
debian
7 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to ...

EPSS

Процентиль: 4%
0.00141
Низкий

5 Medium

CVSS3

Дефекты

CWE-117