Skip to main content

Exposure of Sensitive Information Through Environmental Variables

CVE-2024-11736

Severity Medium
Score 4.9/10

Summary

A security vulnerability has been identified that allows admin users to access sensitive server environment variables and system properties through user-configurable URLs. Specifically, when configuring backchannel logout URLs or admin URLs, admin users can include placeholders like '${env.VARNAME}' or '${PROPNAME}'. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing. This issue affects org.keycloak version prior to 26.0.8.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • HIGH
  • HIGH
  • NONE

CWE-526 - Exposure of Sensitive Information Through Environmental Variables

Environmental variables may contain sensitive information about a remote server.

Advisory Timeline

  • Published