{
  "threat_severity" : "Low",
  "public_date" : "2024-11-21T16:56:00Z",
  "bugzilla" : {
    "description" : "keycloak-quarkus-server: Keycloak path trasversal",
    "id" : "2322447",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2322447"
  },
  "cvss3" : {
    "cvss3_base_score" : "2.7",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-73",
  "details" : [ "A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not.", "A vulnerability was found in Keycloak. A user with high privileges could read sensitive information from a Vault file that is not within the expected context. This attacker must have previous high access to the Keycloak server in order to perform resource creation, for example, an LDAP provider configuration and set up a Vault read file, which will only inform whether that file exists or not." ],
  "statement" : "Red Hat has evaluated this vulnerability. This issue only affects the keycloak-quarkus-server, which is present on the Red Hat Build of Keycloak. No other products are affected.",
  "acknowledgement" : "Red Hat would like to thank Brahim Raddahi (is4u.be) for reporting this issue.",
  "affected_release" : [ {
    "product_name" : "Red Hat build of Keycloak 24",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10175",
    "cpe" : "cpe:/a:redhat:build_keycloak:24::el9",
    "package" : "rhbk/keycloak-operator-bundle:24.0.9-1"
  }, {
    "product_name" : "Red Hat build of Keycloak 24",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10175",
    "cpe" : "cpe:/a:redhat:build_keycloak:24::el9",
    "package" : "rhbk/keycloak-rhel9:24-18"
  }, {
    "product_name" : "Red Hat build of Keycloak 24",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10175",
    "cpe" : "cpe:/a:redhat:build_keycloak:24::el9",
    "package" : "rhbk/keycloak-rhel9-operator:24-18"
  }, {
    "product_name" : "Red Hat build of Keycloak 24.0.9",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10176",
    "cpe" : "cpe:/a:redhat:build_keycloak:24",
    "package" : "org.keycloak/keycloak-quarkus-server"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.0",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10177",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.0::el9",
    "package" : "rhbk/keycloak-operator-bundle:26.0.6-2"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.0",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10177",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.0::el9",
    "package" : "rhbk/keycloak-rhel9:26.0-5"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.0",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10177",
    "cpe" : "cpe:/a:redhat:build_keycloak:26.0::el9",
    "package" : "rhbk/keycloak-rhel9-operator:26.0-6"
  }, {
    "product_name" : "Red Hat build of Keycloak 26.0.6",
    "release_date" : "2024-11-21T00:00:00Z",
    "advisory" : "RHSA-2024:10178",
    "cpe" : "cpe:/a:redhat:build_keycloak:26",
    "package" : "org.keycloak/keycloak-quarkus-server"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat JBoss Enterprise Application Platform 8",
    "fix_state" : "Not affected",
    "package_name" : "org.keycloak/keycloak-quarkus-server",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_application_platform:8"
  }, {
    "product_name" : "Red Hat JBoss Enterprise Application Platform Expansion Pack",
    "fix_state" : "Not affected",
    "package_name" : "org.keycloak/keycloak-quarkus-server",
    "cpe" : "cpe:/a:redhat:jbosseapxp"
  }, {
    "product_name" : "Red Hat Single Sign-On 7",
    "fix_state" : "Out of support scope",
    "package_name" : "org.keycloak/keycloak-quarkus-server",
    "cpe" : "cpe:/a:redhat:red_hat_single_sign_on:7"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2024-10492\nhttps://nvd.nist.gov/vuln/detail/CVE-2024-10492" ],
  "name" : "CVE-2024-10492",
  "csaw" : false
}