Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-5416

Опубликовано: 19 июн. 2025
Источник: redhat
CVSS3: 2.7

Описание

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

Меры по смягчению последствий

Currently, no mitigation is available for this vulnerability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Build of KeycloakkeycloakFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-497
https://bugzilla.redhat.com/show_bug.cgi?id=2369601keycloak-core: Keycloak Environment Information

2.7 Low

CVSS3

Связанные уязвимости

CVSS3: 2.7
nvd
8 месяцев назад

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

CVSS3: 2.7
debian
8 месяцев назад

A vulnerability has been identified in Keycloak that could lead to una ...

CVSS3: 2.7
github
8 месяцев назад

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

2.7 Low

CVSS3