CVE-2024-10973: Red Hat Build Of Keycloak

Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat JBoss Enterprise Application Platform 8
  • Red Hat Red Hat JBoss Enterprise Application Platform Expansion Pack

Published 2024-12-17. Last modified 2026-08-08.