3.7

CVE-2025-10939

Org.keycloak/keycloak-quarkus-server: unable to restrict access to the admin console

Unable to restrict access to the admin console

A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.
Mögliche Gegenmaßnahme
Keycloak Server: Install latest version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerKeycloak
≫
Produkt keycloak
Default Statusunaffected
Version 0
Version < 26.4.4
Status affected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.4
Default Statusaffected
Version 26.4.4-1
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.4
Default Statusaffected
Version 26.4-3
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.4
Default Statusaffected
Version 26.4-3
Version < *
Status unaffected
HerstellerRed Hat
≫
Produkt Red Hat build of Keycloak 26.4.4
Default Statusunaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemKeycloak
≫
Produkt Keycloak Server
Version < 26.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.38% 0.305
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
RedHat 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://bugzilla.redhat.com/show_bug.cgi?id=2398025
https://github.com/keycloak/keycloak/issues/43763
https://github.com/keycloak/keycloak/pull/43765
https://access.redhat.com/errata/RHSA-2025:21370
https://access.redhat.com/errata/RHSA-2025:21371
https://access.redhat.com/security/cve/CVE-2025-10939
https://github.com/keycloak/keycloak/security/advisories/GHSA-vjr8-56p3-fmqq
Third Party Advisory