Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5416

Опубликовано: 19 июн. 2025
Источник: redhat
CVSS3: 2.7
EPSS Низкий

Описание

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of KeycloakkeycloakFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2369601keycloak-core: Keycloak Environment Information

EPSS

Процентиль: 8%
0.00031
Низкий

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
6 месяцев назад

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

CVSS3: 2.7
debian
6 месяцев назад

A vulnerability has been identified in Keycloak that could lead to una ...

CVSS3: 2.7
github
6 месяцев назад

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

EPSS

Процентиль: 8%
0.00031
Низкий

2.7 Low

CVSS3