2.7
/ 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Description
A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of files outside the expected realm context through crafted vault secret lookups. This is a platform-specific variant/incomplete fix of CVE-2024-10492.
Basic Information
ID
CVE-2025-10043
Source
redhat
Published
Sep 5, 2025 at 20:06
Modified
Sep 5, 2025 at 20:19
Affected Product
Vendor
Red Hat
Product
Red Hat Build of Keycloak