Junglewise Threat Intelligence

CVE-2024-11736: Keycloak allows unrestricted admin use of system and environment variables

CVE-2024-11736 · Severity: low · CVSS 3.1 · Published 2025-01-13

Technologies: org.keycloak:keycloak-quarkus-server (Maven). Vendors: Maven.

Executive brief

Keycloak allows unrestricted admin use of system and environment variables

Affected products

  • Maven org.keycloak:keycloak-quarkus-server

Related threats