org.keycloak:keycloak-quarkus-server@25.0.2 vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the org.keycloak:keycloak-quarkus-server package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cleartext Transmission of Sensitive Information

Affected versions of this package are vulnerable to Cleartext Transmission of Sensitive Information due to the improper handling of the KC_CACHE_EMBEDDED_MTLS_ENABLED environment option. This option is ignored, causing JGroups configuration for Infinispan clusters to be visible in plain text. An attacker can read sensitive information by accessing adjacent networks related to JGroups.

How to fix Cleartext Transmission of Sensitive Information?

A fix was pushed into the master branch but not yet published.

[25.0.0,)