Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-11537

11 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2025-11537

7 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
EPSS: Низкий
debian логотип

CVE-2025-11537

7 месяцев назад

A flaw was found in Keycloak. When the logging format is configured to ...

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-gv3v-2cpp-3pmq

7 месяцев назад

Keycloak logs sensitive headers

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-11537

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
0%
Низкий
11 месяцев назад
nvd логотип
CVE-2025-11537

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise.

CVSS3: 5
0%
Низкий
7 месяцев назад
debian логотип
CVE-2025-11537

A flaw was found in Keycloak. When the logging format is configured to ...

CVSS3: 5
0%
Низкий
7 месяцев назад
github логотип
GHSA-gv3v-2cpp-3pmq

Keycloak logs sensitive headers

CVSS3: 5
0%
Низкий
7 месяцев назад

Уязвимостей на страницу