CyberRota Analysis
AI-GeneratedA vulnerability exists in the authentication configuration endpoint of the keycloak-services component, affecting Red Hat Build of Keycloak. This flaw allows administrators with view-only permissions to access sensitive configuration values, including reCAPTCHA secret keys, potentially exposing third-party service credentials to unauthorized users or through logs. Organizations utilizing Keycloak for identity and access management should prioritize remediation to safeguard sensitive information from unauthorized access.
Original NVD Description
A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycloak identity and access management. The issue occurs because the system fails to mask sensitive configuration values, such as reCAPTCHA secret keys, when they are requested by administrators with view-only permissions. This can lead to the exposure of third-party service credentials to unauthorized personnel or through administrative logs.
Related CVEs
Other vulnerabilities affecting the same vendor(s)