Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-11538

10 месяцев назад

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2025-11538

10 месяцев назад

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

CVSS3: 6.8
EPSS: Низкий
debian логотип

CVE-2025-11538

10 месяцев назад

A vulnerability exists in Keycloak's server distribution where enablin ...

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-j4vq-q93m-4683

9 месяцев назад

Keycloak has debug default bind address

CVSS3: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-11538

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2025-11538

A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults to binding the Java Debug Wire Protocol (JDWP) port to all network interfaces (0.0.0.0). This exposes the debug port to the local network, allowing an attacker on the same network segment to attach a remote debugger and achieve remote code execution within the Keycloak Java virtual machine.

CVSS3: 6.8
0%
Низкий
10 месяцев назад
debian логотип
CVE-2025-11538

A vulnerability exists in Keycloak's server distribution where enablin ...

CVSS3: 6.8
0%
Низкий
10 месяцев назад
github логотип
GHSA-j4vq-q93m-4683

Keycloak has debug default bind address

CVSS3: 6.8
0%
Низкий
9 месяцев назад

Уязвимостей на страницу

exploitDog - Комплексное решение для обнаружения, оценки и устранения уязвимостей.