Description
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.
Problem types
Uncontrolled Search Path Element
Product status
26.4.4-1 (rpm) before *
26.4-3 (rpm) before *
26.4-3 (rpm) before *
Timeline
| 2025-09-25: | Reported to Red Hat. |
| 2025-10-27: | Made public. |
Credits
Red Hat would like to thank Sebastian Reigber (AEB) for reporting this issue.
References
access.redhat.com/errata/RHSA-2025:21370 (RHSA-2025:21370)
access.redhat.com/errata/RHSA-2025:21371 (RHSA-2025:21371)
access.redhat.com/security/cve/CVE-2025-10939
bugzilla.redhat.com/show_bug.cgi?id=2398025 (RHBZ#2398025)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.