GHSA-g6qq-c9f9-2772

Suggest an improvement
Source
https://github.com/advisories/GHSA-g6qq-c9f9-2772
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-g6qq-c9f9-2772/GHSA-g6qq-c9f9-2772.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g6qq-c9f9-2772
Aliases
  • CVE-2024-10973
Downstream
Published
2025-02-05T21:18:26Z
Modified
2025-02-05T21:42:03Z
Severity
  • 5.7 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Keycloak on Quarkus CLI option for encrypted JGroups ignored
Details

The env option KC_CACHE_EMBEDDED_MTLS_ENABLED does not work and the jgroups replication configuration is always used in plain. This option worked before in 24 and 22. More info in public issue https://github.com/keycloak/keycloak/issues/34644.

Database specific
{
    "cwe_ids":  [
        "CWE-319"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-02-05T21:18:26Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Maven / org.keycloak:keycloak-quarkus-server

Package

Name
org.keycloak:keycloak-quarkus-server
View open source insights on deps.dev
Purl
pkg:maven/org.keycloak/keycloak-quarkus-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
25.0.0
Fixed
26.0.6

Affected versions

25.*
25.0.0
25.0.1
25.0.2
25.0.3
25.0.4
25.0.5
25.0.6
26.*
26.0.0
26.0.1
26.0.2
26.0.4
26.0.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-g6qq-c9f9-2772/GHSA-g6qq-c9f9-2772.json"