CVE-2024-11736
Executive Summary
Keycloak allows admin users to embed placeholders such as ${env.VARNAME} or ${PROPNAME} in backchannel logout or admin URLs. During URL processing, the server substitutes these with actual environment variable or system property values, enabling privileged users to read sensitive server configuration data. This can lead to information disclosure of credentials, secrets, or other sensitive data. The vulnerability is not yet listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 4.9 (MEDIUM) - Published: 2025-01-14T09:15:20.750 - Last Modified: 2026-08-31T01:16:44.257
Original Description: A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing.
"Accept challenges, so that you may feel the exhilaration of victory."
— George Patton