Description
A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.
Problem types
Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Timeline
| 2025-05-31: | Reported to Red Hat. |
| 2025-06-19: | Made public. |
Credits
Red Hat would like to thank Ibrahim Khorwat (Almadar Aljadid) and Murad Baggas (Almadar Aljadid) for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-5416
bugzilla.redhat.com/show_bug.cgi?id=2369601 (RHBZ#2369601)