{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-05T02:35:56.791","vulnerabilities":[{"cve":{"id":"CVE-2024-11736","sourceIdentifier":"secalert@redhat.com","published":"2025-01-14T09:15:20.750","lastModified":"2026-04-15T00:35:42.020","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"A vulnerability was found in Keycloak. Admin users may have to access sensitive server environment variables and system properties through user-configurable URLs. When configuring backchannel logout URLs or admin URLs, admin users can include placeholders like ${env.VARNAME} or ${PROPNAME}. The server replaces these placeholders with the actual values of environment variables or system properties during URL processing."},{"lang":"es","value":"Se encontró una vulnerabilidad en Keycloak. Los usuarios administradores pueden tener que acceder a variables de entorno de servidor confidenciales y propiedades del sistema a través de URL configurables por el usuario. Al configurar las URL de cierre de sesión de backchannel o las URL de administrador, los usuarios administradores pueden incluir marcadores de posición como ${env.VARNAME} o ${PROPNAME}. El servidor reemplaza estos marcadores de posición con los valores reales de las variables de entorno o las propiedades del sistema durante el procesamiento de URL."}],"metrics":{"cvssMetricV31":[{"source":"secalert@redhat.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N","baseScore":4.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.2,"impactScore":3.6}]},"weaknesses":[{"source":"secalert@redhat.com","type":"Secondary","description":[{"lang":"en","value":"CWE-526"}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2025:0299","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/errata/RHSA-2025:0300","source":"secalert@redhat.com"},{"url":"https://access.redhat.com/security/cve/CVE-2024-11736","source":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2328850","source":"secalert@redhat.com"}]}}]}