Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-11537

Опубликовано: 10 фев. 2026
Источник: nvd
CVSS3: 5
EPSS Низкий

Описание

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

EPSS

Процентиль: 4%
0.00141
Низкий

5 Medium

CVSS3

Дефекты

CWE-117

Связанные уязвимости

CVSS3: 5
redhat
11 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
debian
7 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to ...

CVSS3: 5
github
7 месяцев назад

Keycloak logs sensitive headers

EPSS

Процентиль: 4%
0.00141
Низкий

5 Medium

CVSS3

Дефекты

CWE-117