Description
A flaw was found in Keycloak. The Keycloak guides recommend to not expose /admin path to the outside in case the installation is using a proxy. The issue occurs at least via ha-proxy, as it can be tricked to using relative/non-normalized paths to access the /admin application path relative to /realms which is expected to be exposed.
Problem types
Uncontrolled Search Path Element
Product status
Timeline
| 2025-09-25: | Reported to Red Hat. |
| 2025-10-27: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-10939
bugzilla.redhat.com/show_bug.cgi?id=2398025 (RHBZ#2398025)