RHSA-2024:10176HighCVSS 7.1

Red Hat Security Advisory: Red Hat build of Keycloak 24.0.9 Update

Published
November 21, 2024
Last Modified
August 4, 2026

🔗 CVE IDs covered (5)

📋 Description

CVE-2024-9666 — org.keycloak/keycloak-quarkus-server: Keycloak proxy header handling Denial-of-Service (DoS) vulnerability CVE-2024-10039 — keycloak-core: mTLS passthrough CVE-2024-10270 — org.keycloak:keycloak-services: Keycloak Denial of Service CVE-2024-10451 — org.keycloak:keycloak-quarkus-server: Sensitive Data Exposure in Keycloak Build Process CVE-2024-10492 — keycloak-quarkus-server: Keycloak path trasversal

🎯 Affected products1

  • Red Hat build of Keycloak 24.0.9

✅ Remediation

Before applying the update, back up your existing installation, including all applications, configuration files, databases and database settings, and so on.

🔗 References (8)