Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-11538

Опубликовано: 13 нояб. 2025
Источник: redhat
CVSS3: 6.8
EPSS Низкий

Описание

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug ) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

Отчет

Red Hat evaluates this as a Moderate impact vulnerability due to the requirement of running debug mode and untrusted network. Also, for Red Hat Single Sign-On, this must as well be bound to 0.0.0.0 address, which is not recommended in production scenarios.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1327
https://bugzilla.redhat.com/show_bug.cgi?id=2402622keycloak-server: Debug default bind address

EPSS

Процентиль: 32%
0.00393
Низкий

6.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.8
nvd
10 месяцев назад

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

CVSS3: 6.8
debian
10 месяцев назад

A vulnerability exists in Keycloak's server distribution where enablin ...

CVSS3: 6.8
github
9 месяцев назад

Keycloak has debug default bind address

EPSS

Процентиль: 32%
0.00393
Низкий

6.8 Medium

CVSS3