CVE-2025-11537
MEDIUM5.0EPSS 0.01%Keycloak logs sensitive headers
發布日:2026/2/10修改日:2026/4/9
描述
A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise. Patches are available, see: - https://github.com/keycloak/keycloak/releases/tag/26.4.11 - https://github.com/keycloak/keycloak/releases/tag/26.5.6 - https://github.com/keycloak/keycloak/releases/tag/26.6.0
受影響套件(1)
- Maven/org.keycloak:keycloak-quarkus-serverfrom 0, < 26.5.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.0 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N |
參考連結(8)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2025-11537
- PATCHhttps://github.com/keycloak/keycloak
- WEBhttps://access.redhat.com/security/cve/CVE-2025-11537
- WEBhttps://bugzilla.redhat.com/show_bug.cgi?id=2402616
- WEBhttps://github.com/keycloak/keycloak/commit/137a35c1109ff43a305f26264978a3ea21452373
- WEBhttps://github.com/keycloak/keycloak/commit/5a3cdb7c4ccbf83ffc926f70d655a60269d7207b
- WEBhttps://github.com/keycloak/keycloak/commit/9622f550a6e565b29a3a37454421f08626791a6c
- WEBhttps://www.keycloak.org/server/logging#_change_log_formatpattern