Impact
The flaw in the authentication configuration endpoint of the keycloak-services component causes the system to expose sensitive configuration values, such as reCAPTCHA secret keys, when accessed by administrators with view-only permissions. This allows an attacker with view-only admin rights to read third‑party service credentials or see them in administrative logs, thereby compromising confidentiality. The vulnerability does not provide direct code execution or privilege escalation, but it enables leakage of credentials that could be used to compromise external services or downstream systems.
Affected Systems
Products affected include Red Hat Build of Keycloak, Red Hat Data Grid 8, Red Hat JBoss Enterprise Application Platform Expansion Pack, and Red Hat Single Sign‑On 7. No specific version information is provided in the current data.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity, and the EPSS score of < 1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is that an adversary must already possess view‑only administrator privileges to read the configuration endpoint; no additional conditions or exploits are required. Consequently, the overall risk is limited, but the exposure of secret keys remains a serious concern if those keys grant access to critical third‑party services. The vendor has indicated that no workaround is available.
OpenCVE Enrichment