CVE-2025-11537

MEDIUM5.0EPSS 0.01%

Keycloak logs sensitive headers

發布日:2026/2/10修改日:2026/4/9

描述

A flaw was found in Keycloak. When the logging format is configured to a verbose, user-supplied pattern (such as the pre-defined 'long' pattern), sensitive headers including Authorization and Cookie are disclosed to the logs in cleartext. An attacker with read access to the log files can extract these credentials (e.g., bearer tokens, session cookies) and use them to impersonate users, leading to a full account compromise. Patches are available, see: - https://github.com/keycloak/keycloak/releases/tag/26.4.11 - https://github.com/keycloak/keycloak/releases/tag/26.5.6 - https://github.com/keycloak/keycloak/releases/tag/26.6.0

受影響套件(1)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM5.0CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

參考連結(8)