CVE-2024-10451 - CVE House
Back to Database
Status published Medium CVE-2024-10451

Org.keycloak:keycloak-quarkus-server: sensitive data exposure in keycloak build process

Vulnerability Description

A flaw was found in Keycloak. This issue occurs because sensitive runtime values, such as passwords, may be captured during the Keycloak build process and embedded as default values in bytecode, leading to unintended information disclosure. In Keycloak 26, sensitive data specified directly in environment variables during the build process is also stored as a default values, making it accessible during runtime. Indirect usage of environment variables for SPI options and Quarkus properties is also vulnerable due to unconditional expansion by PropertyMapper logic, capturing sensitive data as default values in all Keycloak versions up to 26.0.2.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10451

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Red Hat would like to thank Steven Hawkins for reporting this issue.

Affected Vendor

Affected Software

Red Hat build of Keycloak 24, Red Hat build of Keycloak 24.0.9, Red Hat build of Keycloak 26.0, Red Hat build of Keycloak 26.0.6, Red Hat JBoss Enterprise Application Platform 8, Red Hat Single Sign-On 7
Vulnerable Versions:
24.0.9-1, 24-18, 26.0.6-2, 26.0-5, 26.0-6

Timeline

Official Publish: November 25th, 2024
Last Modified: November 11th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)