CVE 2.7 LOW

Keycloak: incomplete fix of cve-2024-10492_CVE-2025-10043

2.7 / 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

Description

A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of files outside the expected realm context through crafted vault secret lookups. This is a platform-specific variant/incomplete fix of CVE-2024-10492.

Basic Information

ID CVE-2025-10043
Source redhat
Published Sep 5, 2025 at 20:06
Modified Sep 5, 2025 at 20:19

Affected Product

Vendor Red Hat
Product Red Hat Build of Keycloak

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.