A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of files outside the expected realm context through crafted vault secret lookups. This is a platform-specific variant/incomplete fix of CVE-2024-10492.
Metrics
Affected Vendors & Products
References
History
Fri, 05 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 05 Sep 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal validation flaw exists in Keycloak’s vault key handling on Windows. The previous fix for CVE-2024-10492 did not account for the Windows file separator (\). As a result, a high-privilege administrator could probe for the existence of files outside the expected realm context through crafted vault secret lookups. This is a platform-specific variant/incomplete fix of CVE-2024-10492. | |
Title | Keycloak: incomplete fix of cve-2024-10492 | |
First Time appeared |
Redhat
Redhat build Keycloak |
|
Weaknesses | CWE-73 | |
CPEs | cpe:/a:redhat:build_keycloak: | |
Vendors & Products |
Redhat
Redhat build Keycloak |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-09-05T20:19:20.728Z
Reserved: 2025-09-05T18:12:23.630Z
Link: CVE-2025-10043

Updated: 2025-09-05T20:19:16.627Z

Status : Received
Published: 2025-09-05T20:15:34.220
Modified: 2025-09-05T20:15:34.220
Link: CVE-2025-10043

No data.

No data.