A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.
Workaround:
The product does not properly prevent sensitive system-level information from being accessed by unauthorized actors who do not have the same level of access to the underlying system as the product does.
Link | Tags |
---|---|
https://access.redhat.com/security/cve/CVE-2025-5416 | vdb entry |
https://bugzilla.redhat.com/show_bug.cgi?id=2369601 | issue tracking |