CVE-2024-4540: Red Hat Build Of Keycloak

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an information disclosure vulnerability.

Affected products

  • Red Hat Red Hat Build Of Keycloak
  • Red Hat Red Hat Build Of Keycloak 22: before 22.0.11-2 (fixed in 22.0.11-2); before 22-15 (fixed in 22-15); before 22-18 (fixed in 22-18)
  • Red Hat Red Hat Build Of Keycloak 24: before 24.0.5-2 (fixed in 24.0.5-2); before 24-10 (fixed in 24-10)
  • Red Hat Red Hat Single Sign-On 7
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 7: before 0:18.0.14-1.redhat_00001.1.el7sso (fixed in 0:18.0.14-1.redhat_00001.1.el7sso)
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 8: before 0:18.0.14-1.redhat_00001.1.el8sso (fixed in 0:18.0.14-1.redhat_00001.1.el8sso)
  • Red Hat Red Hat Single Sign-On 7.6 For Rhel 9: before 0:18.0.14-1.redhat_00001.1.el9sso (fixed in 0:18.0.14-1.redhat_00001.1.el9sso)
  • Red Hat Rhel-8 Based Middleware Containers: before 7.6-49 (fixed in 7.6-49)

Published 2024-06-03. Last modified 2026-10-09.