Description

A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it requires an already authenticated user, the /admin/serverinfo endpoint can inadvertently provide sensitive environment information.

INFO

Published Date :

2025-06-20T16:04:05.694Z

Last Modified :

2025-11-21T07:36:39.759Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-5416 vulnerability.

Vendors Products
Redhat
  • Build Keycloak
  • Keycloak

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact