CVE-2024-10973
CVE-2024-10973
Título es
CVE-2024-10973
Mar, 17/12/2024 – 23:15
Tipo
CWE-319
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-10973
Descripción en
A vulnerability was found in Keycloak. The environment option `KC_CACHE_EMBEDDED_MTLS_ENABLED` does not work and the JGroups replication configuration is always used in plain text which can allow an attacker that has access to adjacent networks related to JGroups to read sensitive information.
18/12/2024
18/12/2024
Vector CVSS:3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
5.70
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
MEDIUM
Referencias
Enviar en el boletín
Off
